logo

Linux Kernel Level ARP Hijacking/Spoofing Utility

ID: 65b688bd-06fc-5750-881d-8df3d26d9cb9

STIX ID: report--65b688bd-06fc-5750-881d-8df3d26d9cb9

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-23

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome, Edge, Brave, Opera (and variants), Vivaldi, and Firefox; it bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and implements multiple evasion techniques to reduce EDR detection. The report outlines usage, extracted data, an example attack scenario (fast credential theft enabling cloud account takeover and lateral movement), detection signals (IElevator calls, unexpected process injection, non-browser reads of Login Data/Cookies/Web Data), and mitigations such as using external password managers and monitoring relevant behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.