logo

Aclpwn.Py – Exploit ACL Based Privilege Escalation Paths in Active Directory

ID: 4f682a50-9beb-527f-8af7-e74ac5872070

STIX ID: report--4f682a50-9beb-527f-8af7-e74ac5872070

Feed Name: Darknet

Threat Score
75/100

Date Published: 2021-07-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential harvesting tool that targets Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium instance and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS keys where applicable, and outputs structured JSON, while employing evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report assesses attack scenarios, detection opportunities (injection into browser processes, IElevator calls, unauthorized reads of browser SQLite files), and mitigation guidance including using external credential managers and EDR rules focused on browser process behaviour.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.