logo

Generate Reverse TCP Backdoors & Malicious .LNK Files

ID: 888b9d56-d479-581d-b776-b62247c7470a

STIX ID: report--888b9d56-d479-581d-b776-b62247c7470a

Feed Name: Darknet

Threat Score
70/100

Date Published: 2010-10-18

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a public post‑exploitation tool that extracts browser‑stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major browsers on Windows by bypassing App‑Bound Encryption for Chromium‑based browsers (using a headless process, Early Bird APC DLL injection and the IElevator COM interface) and handling DPAPI/NSS models for other browsers; it outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication and a custom SQLite parser), and presents a high-risk vector for cloud account takeover and lateral movement on compromised developer or user workstations, with detection opportunities focused on anomalous headless browser instantiation, non‑browser reads of browser SQLite databases, and IElevator calls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.