logo

Another Week Another Mass Domain Hijacking

ID: 41bf08c1-36a4-5ea2-8830-1d8fc19c915a

STIX ID: report--41bf08c1-36a4-5ea2-8830-1d8fc19c915a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-07-19

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and tokens from Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by combining a compiled executable with a DLL that is injected into a headless browser process to bypass App‑Bound Encryption (via the IElevator COM interface) and retrieve encryption keys; it supports DPAPI and NSS decryption for other browsers, outputs structured JSON, includes operational evasion techniques, and is presented with usage, detection opportunities, and mitigation recommendations for defenders and red-team operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.