logo

India Central Bureau of Investigation (CBI) Site Still Down

ID: 42695e53-61d4-5888-aee2-64a6f3742ec4

STIX ID: report--42695e53-61d4-5888-aee2-64a6f3742ec4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-12-07

Date Updated: 2026-05-14

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool (targeting Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption) that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history into structured JSON. The tool uses DLL injection into a spawned headless Chromium process (Early Bird APC + IElevator COM interface) to decrypt app_bound_encrypted_key, includes various evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom sqlite parser), and is presented as a red-team utility with guidance on detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.