logo

Kaspersky Lab Alleged Customer Database Hack From SQL Injection Flaw

ID: 6fedfaef-b78b-5881-ace0-424d7e3a3a68

STIX ID: report--6fedfaef-b78b-5881-ace0-424d7e3a3a68

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-02-10

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium-based and Firefox browsers on Windows. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium instance and injecting a DLL to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser). The report describes usage, output, attack scenarios, detection opportunities (process injection, IElevator calls, reads of browser SQLite DBs), and mitigation recommendations such as using out-of-browser credential managers and enhanced EDR monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.