logo

Security System Analyzer an OVAL Based Scanner

ID: 813aefad-6228-5b50-ade3-e6181d55392c

STIX ID: report--813aefad-6228-5b50-ade3-e6181d55392c

Feed Name: Darknet

Threat Score
70/100

Date Published: 2007-04-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool designed to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium‑based and Firefox browsers on Windows. It uses a headless Chromium spawn plus Early Bird APC DLL injection and the IElevator COM interface to bypass Chrome's App‑Bound Encryption (Chrome 127+), handles DPAPI or NSS where appropriate, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report describes usage, output (JSON), an attack scenario emphasizing rapid cloud/SaaS account access, detection opportunities, and mitigations such as using external credential managers and EDR monitoring of IElevator and unexpected headless browser processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.