logo

German Police Creating Law Enforcement Trojan

ID: 64476ce3-51ce-59c1-b86b-4830a017ee4c

STIX ID: report--64476ce3-51ce-59c1-b86b-4830a017ee4c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-02-01

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session artifacts from major Chromium-based and Firefox browsers on Windows. It implements a sophisticated App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve the decryption key; it also handles DPAPI and NSS-encrypted stores for other browsers. The tool outputs structured JSON, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is positioned for red-team/assumed-breach use but represents a high-risk capability for real-world credential theft and cloud account takeover if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.