logo

Credential Stuffing in 2025 – How Combolists, Infostealers and Account Takeover Became an Industry

ID: 7103e588-d196-50b4-b5e1-82255fc0cfd7

STIX ID: report--7103e588-d196-50b4-b5e1-82255fc0cfd7

Feed Name: Darknet

Threat Score
70/100

Date Published: 2026-03-11

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox). The report explains its App-Bound Encryption bypass (IElevator COM invoked via DLL injected into a headless Chromium process), DPAPI/NSS handling for other browsers, evasion techniques, example attack scenarios, detection opportunities, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.