logo

Happy Chinese New Year 2011

ID: 854278d3-b47f-5efa-b041-20d8a5fb514e

STIX ID: report--854278d3-b47f-5efa-b041-20d8a5fb514e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-02-02

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a public post‑exploitation tool that extracts credentials and session artifacts from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium instance and injecting a DLL to call the IElevator COM interface, uses DPAPI extraction for some Chromium forks and NSS decryption for Firefox, and outputs structured JSON of cookies, saved logins, OAuth tokens, credit cards, autofill entries, history, and bookmarks — enabling rapid lateral movement and cloud account takeover in assumed‑breach scenarios while including operational evasion techniques to hinder EDR detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.