logo

The Enemy Within The Firewall

ID: 5475938c-848e-51b4-9e4f-8636acbe4f69

STIX ID: report--5475938c-848e-51b4-9e4f-8636acbe4f69

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-05-25

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from major Chromium-based browsers and Firefox on Windows. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI extraction for Opera-derived browsers, and NSS decryption for Firefox; the tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parsing), outputs structured JSON, and is positioned for red-team/assumed-breach use while also posing a realistic threat if abused by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.