logo

Second Order – Subdomain Takeover Scanner Tool

ID: 67fb14ab-acb8-5f12-8ebc-ee477e0b9380

STIX ID: report--67fb14ab-acb8-5f12-8ebc-ee477e0b9380

Feed Name: Darknet

Threat Score
78/100

Date Published: 2020-04-30

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave (including an App‑Bound Encryption bypass), Opera-family browsers (DPAPI), and Firefox (NSS). The analysis describes how the tool injects a DLL into a headless Chromium process to use the IElevator COM interface to decrypt app_bound_encrypted_key, parses on-disk SQLite/JSON stores to extract high-value artifacts (saved logins, cookies, OAuth tokens, autofill, credit cards), and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and detection/mitigation recommendations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.