logo

yahoo password grabber

ID: 44268bd2-27eb-5ef4-bfb2-8cb0707be880

STIX ID: report--44268bd2-27eb-5ef4-bfb2-8cb0707be880

Feed Name: Darknet

Threat Score
70/100

Date Published: 2007-06-08

Date Updated: 2026-05-18

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Opera GX/Vivaldi via DPAPI, and Firefox via NSS). It achieves Chrome/Chromium key recovery by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, returns decrypted keys to the executable, parses browser SQLite/JSON stores, and outputs structured JSON; the tool includes multiple evasion techniques and provides detection and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.