logo

Security Companies Fight Against Microsoft Security Center

ID: 8ebb45b4-96c8-5366-b69a-0735f0de90b5

STIX ID: report--8ebb45b4-96c8-5366-b69a-0735f0de90b5

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-10-26

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract saved credentials, session cookies, OAuth tokens, credit card data, autofill entries, history, and bookmarks. The report describes its architecture (an executable plus a DLL injected into a headless Chromium process using Early Bird APC to decrypt app_bound_encrypted_key), evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, detection opportunities, and its relevance for red-team testing and assessing credential exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.