logo

Your Employees Don’t Care About Your Data

ID: 884dd6fd-e34f-5c64-b43f-9a4cac7911d9

STIX ID: report--884dd6fd-e34f-5c64-b43f-9a4cac7911d9

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-03

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that extracts cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report covers usage, an attack scenario demonstrating fast credential extraction for lateral/cloud account takeover, detection opportunities (process injection, headless browser instantiation, reads of browser SQLite DBs, IElevator calls) and mitigations (use of standalone credential managers and EDR rules monitoring IElevator and headless browser behavior).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.