logo

Car Immobilisers Using Weak Encryption Schemes

ID: 81a3330c-c8b6-5698-988e-c28b188421d2

STIX ID: report--81a3330c-c8b6-5698-988e-c28b188421d2

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-12-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history) from Chromium-based browsers and Firefox. It achieves this by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt App-Bound Encryption keys (Chrome/Edge/Brave), retrieves DPAPI keys for Opera-family browsers, and uses NSS decryption for Firefox; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parser) and outputs structured JSON for red-team use, plus guidance for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.