logo

HD Moore’s Company BreakingPoint Suffers DNS Attack

ID: 5599bb3c-4e19-5686-87b9-c4539d49d795

STIX ID: report--5599bb3c-4e19-5686-87b9-c4539d49d795

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-08-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill data, history, and bookmarks. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless browser and injecting a DLL using Early Bird APC to access the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and contains multiple evasion features; the report also provides usage examples, an attack scenario, and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.