logo

Training Environment For Web Application Security

ID: 8be87f52-2160-5e2e-ad6a-044346cc1e64

STIX ID: report--8be87f52-2160-5e2e-ad6a-044346cc1e64

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-03-01

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major Chromium-based browsers and Firefox by bypassing App‑Bound Encryption (Chrome/Edge/Brave) via DLL injection into a headless Chromium process using Early Bird APC and the IElevator COM interface; it also handles DPAPI-based browsers (Opera, Vivaldi) and NSS-based Firefox decryption, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and the report provides attack scenarios, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.