logo

More Drama About Hillary Clinton's E-mail Leak

ID: 81bac2d1-db91-5a80-af16-74b574082283

STIX ID: report--81bac2d1-db91-5a80-af16-74b574082283

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-10-14

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data and browsing history from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses DLL injection into a headless Chromium process (Early Bird APC) to leverage the IElevator COM interface and decrypt app_bound_encrypted_key, includes multiple operational evasion techniques, outputs structured JSON for red-team use, and highlights detection and mitigation opportunities such as monitoring IElevator calls, headless browser instantiation, and unexpected reads of browser SQLite files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.