logo

Microsoft Takes an Effort at Cutting Down Blogspam

ID: 79d277a4-8cab-5a22-b973-244b2994da6d

STIX ID: report--79d277a4-8cab-5a22-b973-244b2994da6d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-08-13

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from major Chromium-based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt encryption keys, handles DPAPI/NSS models for other browsers, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red‑team utility to test the blast radius of compromised developer endpoints while also representing a realistic infostealer capability for attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.