logo

Technitium FREE MAC Address Changer v5 R2 Released for Windows

ID: 42cc761c-c3c3-5d91-b7a0-25c59a4b7fb6

STIX ID: report--42cc761c-c3c3-5d91-b7a0-25c59a4b7fb6

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-05-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from Chrome, Edge, Brave, Opera, Vivaldi, Opera GX, and Firefox. It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless browser and injecting a DLL (Early Bird APC injection) to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption where applicable, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON for red-team use, and provides detection and mitigation guidance such as monitoring IElevator COM calls, unexpected process injection into Chromium, headless browser instantiation, and non-browser reads of browser SQLite databases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.