logo

Shadowserver Battles the Botnets

ID: 6e0f7c01-4c49-5e6e-8709-9f6838339db4

STIX ID: report--6e0f7c01-4c49-5e6e-8709-9f6838339db4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-06-28

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox by bypassing App‑Bound Encryption (via headless Chromium + injected DLL and IElevator COM), using DPAPI extraction, and NSS decryption for Firefox. The report details its operation, evasion techniques, supported browsers and data types, an example attack scenario, detection opportunities, and mitigation recommendations to evaluate enterprise exposure to browser-based credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.