logo

Open Vulnerability Assessment System (Nessus is Back!)

ID: 4d589bc2-1751-5ea0-9ddb-f086f1a6948f

STIX ID: report--4d589bc2-1751-5ea0-9ddb-f086f1a6948f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-08-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI/NSS keys for other browsers, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red-team/assumed-breach testing tool while describing detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.