logo

HoneyDrive 3 Released – New Honeypot Download Distro ISO

ID: 4080023f-b59d-599b-868f-18fc0c1fae79

STIX ID: report--4080023f-b59d-599b-868f-18fc0c1fae79

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-08-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool (publicly released) that harvests browser-stored secrets from major Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, retrieves DPAPI keys for some browsers, and handles Firefox NSS decryption directly. The tool extracts cookies, saved logins, OAuth refresh tokens, credit card data, autofill and history, outputs structured JSON, includes multiple EDR-evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and includes detection/mitigation recommendations, making it useful for red teams and a relevant threat for credential and cloud account takeover scenarios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.