logo

Free Network Intrusion Detection & Prevention System

ID: 4b837385-c3f5-52b5-ae2b-bac383ff8b0f

STIX ID: report--4b837385-c3f5-52b5-ae2b-bac383ff8b0f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-11-01

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a pre-compiled Windows post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) across Chromium-based and Firefox browsers; it implements an App-Bound Encryption bypass for Chrome/Brave/Edge by injecting a DLL into a headless Chromium process (Early Bird APC) and using the IElevator COM interface to decrypt keys, and uses DPAPI/NSS handling for other browsers. The tool targets red-team/assumed-breach use cases, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is relevant for assessing the blast radius of compromised developer workstations and detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.