logo

4f: The File Format Fuzzing Framework

ID: 860c8d32-3e0b-5515-bd46-58ca0afd18ab

STIX ID: report--860c8d32-3e0b-5515-bd46-58ca0afd18ab

Feed Name: Darknet

Threat Score
80/100

Date Published: 2009-09-04

Date Updated: 2026-05-14

...
...

DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox browsers. It implements a bypass of Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, supports DPAPI and NSS decryption for other browsers, includes multiple operational evasion techniques, and outputs structured JSON for red-team assessment and credential replay.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.