logo

Phishing Fraud Cases Growing in the UK

ID: 42b740d9-7580-591f-9ff2-69a115ba3b0b

STIX ID: report--42b740d9-7580-591f-9ff2-69a115ba3b0b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-01-23

Date Updated: 2026-05-08

...
...

### Executive summary DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium- and Gecko-based browsers; it bypasses App-Bound Encryption in modern Chromium builds by injecting a DLL into a headless Chromium process to access the IElevator COM interface and also handles DPAPI and NSS-decrypted stores. The report details usage, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), detection opportunities, and mitigation recommendations, emphasizing the tool's relevance for red teams and its high-risk implications for cloud and SaaS account takeover from compromised developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.