logo

Spammers Target Social Networking Sites

ID: 6dd90de4-f0fa-5631-982e-3774c4dae3f1

STIX ID: report--6dd90de4-f0fa-5631-982e-3774c4dae3f1

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-05-22

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface to decrypt the app-bound key, supports DPAPI- and NSS-based decryption for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report covers usage, extracted output, an attack scenario demonstrating rapid credential extraction and session replay, detection opportunities (process injection, IElevator calls, non-browser reads of browser SQLite DBs) and mitigation recommendations (use of external credential managers and EDR monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.