logo

Information about the Internet Explorer Exploit createTextRange Code Execution

ID: 89e369bb-65f3-5a49-be2d-f6ca97b433a6

STIX ID: report--89e369bb-65f3-5a49-be2d-f6ca97b433a6

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-26

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, and browsing history from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a spawned headless Chromium process to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques for EDR, and outputs structured JSON for red-team or adversary use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.