logo

Julie Amero Spyware Case Finally Comes To An End

ID: 5a6c0747-ae63-5583-ae9a-9e502751f315

STIX ID: report--5a6c0747-ae63-5583-ae9a-9e502751f315

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-11-24

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to leverage the IElevator COM interface, handles DPAPI and NSS for other browsers, and outputs structured JSON of cookies, saved logins, OAuth refresh tokens, credit card data, autofill, and history. The report documents operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, file-handle duplication), usage examples, detection opportunities, and mitigations, noting its suitability for red team testing and the real risk it poses to compromised developer workstations and enterprise SaaS access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.