logo

Reaper – Unified Application Security Testing with AI Support

ID: 6ffcece8-69ed-53f0-9072-84689882ad6a

STIX ID: report--6ffcece8-69ed-53f0-9072-84689882ad6a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-10-27

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) across Chromium-based browsers and Firefox. The report details its operation — spawning a headless Chromium process, injecting a DLL via Early Bird APC to leverage the IElevator COM interface and decrypt App-Bound Encryption keys, handling DPAPI and NSS models for other browsers, and implementing evasion techniques — and discusses attack scenarios, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.