logo

Rogue Access Point (evilAP) And MiTM Attack Tool

ID: 8f3f8c2d-bc8d-5047-9276-2919c76ab53d

STIX ID: report--8f3f8c2d-bc8d-5047-9276-2919c76ab53d

Feed Name: Darknet

Threat Score
78/100

Date Published: 2016-09-20

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses App‑Bound Encryption in modern Chromium builds by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key, and also handles DPAPI and NSS decryption models; the tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON to facilitate post‑exploitation reuse, making it a high‑impact capability for lateral movement and SaaS account takeover in enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.