logo

PentestGPT – AI-Powered Penetration Testing Assistant

ID: 7cbd2536-7988-54c4-8469-f52e50f3a1ce

STIX ID: report--7cbd2536-7988-54c4-8469-f52e50f3a1ce

Feed Name: Darknet

Threat Score
78/100

Date Published: 2025-04-14

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, performing Early Bird APC DLL injection to use the IElevator COM interface, and returns decrypted keys to decrypt on-disk SQLite/JSON stores; Opera-family browsers use DPAPI recovery and Firefox uses NSS decryption. The report covers operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), output and usage, a realistic attack scenario against authenticated developer workstations, and detection/mitigation guidance for EDR and policy controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.