logo

ARPWatch-NG ARP Flooding/Spoofing Protection/Detection

ID: 710e9bf7-af77-5f11-8779-103b2c5c8112

STIX ID: report--710e9bf7-af77-5f11-8779-103b2c5c8112

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-10-26

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool that extracts credentials and session tokens from Chromium-based and Firefox browsers by spawning a headless Chromium process and injecting a DLL to bypass App‑Bound Encryption (Chrome 127+), and by retrieving DPAPI/NSS keys for other browsers; the report explains supported browsers and data types, technical implementation (Early Bird APC injection, IElevator COM use), operational evasion features, detection opportunities, and mitigation advice, concluding it is a credible red-team infostealer with significant cloud account takeover and lateral-movement implications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.