logo

HiddenWall – Create Hidden Kernel Modules

ID: 73776019-3028-5991-bbef-122b8f3455a7

STIX ID: report--73776019-3028-5991-bbef-122b8f3455a7

Feed Name: Darknet

Threat Score
75/100

Date Published: 2019-09-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, returns decrypted keys to the executable, parses SQLite/JSON stores, and outputs structured JSON; the report covers capabilities, evasion, an attack scenario demonstrating cloud account takeover risk, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.