logo

Money Lost Due to Cybercrime Down Again This Year!

ID: 65f480f5-fe5e-5e5f-ba52-d0e8bdd46250

STIX ID: report--65f480f5-fe5e-5e5f-ba52-d0e8bdd46250

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-06-19

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based browsers and Firefox. It bypasses App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI/NSS keys where applicable, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red team/assumed-breach testing tool; defenders should monitor for unexpected browser process injection, IElevator calls, and non-browser access to browser SQLite files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.