logo

CredMaster – Anonymous AWS‑Backed Password Spraying Toolkit

ID: 78707820-a401-5ad5-8601-2cf1c45731a7

STIX ID: report--78707820-a401-5ad5-8601-2cf1c45731a7

Feed Name: Darknet

Threat Score
72/100

Date Published: 2025-07-21

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chromium‑based and Gecko‑based browsers on Windows, using a headless Chromium + injected DLL to bypass Chrome's App‑Bound Encryption via the IElevator COM interface (and DPAPI/NSS handling for other browsers) to extract cookies, saved passwords, OAuth refresh tokens, credit cards, autofill data, and history; the report describes its components, operational evasion techniques, extraction output, usage examples, detection opportunities, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.