logo

Posts Restored & Business (almost) Back to Usual

ID: 48ec7249-b9e8-5bec-bfca-bfe21318d311

STIX ID: report--48ec7249-b9e8-5bec-bfca-bfe21318d311

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-10-16

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that targets major Chromium-based browsers and Firefox to extract saved logins, session cookies, OAuth refresh tokens, credit card numbers, autofill data and browsing history. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC + IElevator COM interface) to decrypt the app_bound_encrypted_key, handles DPAPI and NSS decryption for other browsers, outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is presented as a red-team tool useful for assessing the realistic credential blast radius but also usable by adversaries for lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.