logo

Source Code & Software Security Analysis with BogoSec

ID: 4dc2738c-1db0-5243-b502-e4dc141e069e

STIX ID: report--4dc2738c-1db0-5243-b502-e4dc141e069e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-05-16

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool for Windows that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill entries and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to leverage the IElevator COM interface, parses on-disk SQLite/JSON stores, and writes structured JSON output; the report covers capabilities, usage, attack scenarios, evasion techniques, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.