logo

Cyber Security Incident Management Platform

ID: 91f49899-b66d-57d3-bf76-a3ed9dbd780e

STIX ID: report--91f49899-b66d-57d3-bf76-a3ed9dbd780e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-08-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts credentials and session data from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS secrets where applicable, and outputs structured JSON of cookies, saved logins, OAuth tokens, credit card data, autofill, and history; the report assesses operational use, detection vectors, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.