logo

Hackers Target Home Users for Cash

ID: 54e266dd-90e0-554a-84fb-47ca6439de58

STIX ID: report--54e266dd-90e0-554a-84fb-47ca6439de58

Feed Name: Darknet

Threat Score
78/100

Date Published: 2006-11-01

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and tokens from Windows hosts (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + DLL injection (Early Bird APC) to decrypt app_bound_encrypted_key via the IElevator COM interface, extracts credentials from on-disk SQLite/JSON stores, includes multiple EDR-evasion features, and outputs structured JSON for red-team or malicious reuse — exposing a high-impact attack surface for cloud/SaaS account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.