logo

Odysseus Proxy for MITM Attacks Testing Security of Web Applications.

ID: 870b332c-9c48-523a-af03-2952cc39f669

STIX ID: report--870b332c-9c48-523a-af03-2952cc39f669

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-10-22

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium-based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox; the tool includes operational evasion techniques, outputs structured JSON, and is intended for red-team assumed‑breach testing but could be repurposed by real attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.