logo

High-Performance (Open Source) Web Application Security Scanner Framework

ID: 77991fd8-e49e-5f07-bf3f-c915b4480084

STIX ID: report--77991fd8-e49e-5f07-bf3f-c915b4480084

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-01-09

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation Windows tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, etc.) across Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, includes DPAPI and NSS handling for other browsers, and incorporates evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report describes attack scenarios, output formats, detection opportunities (injection, IElevator calls, reads of browser SQLite DBs), and mitigation guidance including using dedicated credential managers and EDR policies that monitor IElevator and headless browser behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.