Fingerprint & Identify Web Application Firewall (WAF) Products
ID: 8dbe87da-b081-54d2-92a2-2dede315b900
STIX ID: report--8dbe87da-b081-54d2-92a2-2dede315b900
Feed Name: Darknet
Threat Score
**DumpBrowserSecrets** is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium‑based and Gecko‑based browsers by abusing an App‑Bound Encryption bypass (IElevator COM) via Early Bird APC DLL injection into a headless browser process, with DPAPI/NSS handling for other browsers and multiple evasion features designed for red‑team and adversary simulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
