logo

Open Source Blamed for Rootkits?

ID: 6047b37a-56d7-5008-97ab-296e71c05445

STIX ID: report--6047b37a-56d7-5008-97ab-296e71c05445

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-05-13

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool targeting Chromium- and Gecko-based browsers that bypasses Chrome's App‑Bound Encryption (via IElevator COM usage inside an injected DLL) and leverages DPAPI/NSS decryption to extract cookies, saved credentials, OAuth refresh tokens, credit card data, autofill entries, and browsing history into JSON. The report documents installation, usage examples, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), an attack scenario demonstrating rapid credential extraction and session replay, and detection/mitigation guidance for enterprise defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.