logo

Python Windows Backdoor With Gmail Command & Control

ID: 4252a157-0889-5b89-b71f-ad7701a1df81

STIX ID: report--4252a157-0889-5b89-b71f-ad7701a1df81

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-05-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that retrieves saved logins, cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chromium-based and Firefox browsers; it uses a DLL injected into a headless Chromium process to bypass Chrome's App-Bound Encryption via the IElevator COM interface and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report covers supported browsers, extraction output, usage examples, detection indicators (unexpected process injection, IElevator usage, reads of browser SQLite files), and mitigation recommendations such as using external credential managers and EDR heuristics that monitor headless browser instantiation and IElevator calls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.