logo

Caller ID Spoofing to be Made Illegal in the USA

ID: 4ea20a93-2087-5955-95af-6e57d4ac62a5

STIX ID: report--4ea20a93-2087-5955-95af-6e57d4ac62a5

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-08-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) across Chromium-based and Gecko-based browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface and decrypt the app_bound_encrypted_key, while using DPAPI retrieval for Opera-family browsers and NSS decryption for Firefox; outputs are written as structured JSON and the tool includes multiple evasion features aimed at EDR resistance, making it useful for red-team testing and potentially attractive to malicious operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.