logo

Hackers Get Hold Of Wildcard Google SSL Certificate

ID: 7cfc7f10-3b94-5c0b-9cd2-8a4795260870

STIX ID: report--7cfc7f10-3b94-5c0b-9cd2-8a4795260870

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-08-30

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser‑stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill entries, history, and bookmarks) from Chromium‑based browsers and Firefox. It bypasses Chrome’s App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI keys for some Chromium forks, and handles Firefox via NSS decryption; the README documents usage, evasion (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), detection opportunities, and red-team relevance, showing how recovered tokens can enable cloud account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.