logo

June Commenter of the Month Competition Winner Daniel and his Prizes

ID: 89bef678-f5f5-5633-9e9e-eaa5b225c56c

STIX ID: report--89bef678-f5f5-5633-9e9e-eaa5b225c56c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-08-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-extraction tool that targets major browsers (Chrome, Edge, Brave, Opera-family, Vivaldi, and Firefox) to harvest saved passwords, cookies, OAuth refresh tokens, credit cards, autofill data, and history. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (Early Bird APC injection), retrieves decryption keys (or DPAPI/NSS keys for other browsers), parses browser SQLite/JSON stores, and outputs structured JSON; the tool includes multiple evasion techniques and is pitched for red-team use while also representing a realistic threat vector for credential theft in enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.