logo

Exploit Next Generation SQL Fingerprint (ESF)

ID: 9293a120-4f31-5f3c-bb75-8fc359938b03

STIX ID: report--9293a120-4f31-5f3c-bb75-8fc359938b03

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-10-12

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored secrets from major Windows browsers (Chrome, Edge, Brave, Opera/Opera GX, Vivaldi, Firefox). It bypasses Chromium App‑Bound Encryption by spawning a headless browser and injecting a DLL to use the IElevator COM interface (Early Bird APC injection), retrieves DPAPI/NSS keys where applicable, and outputs structured JSON containing cookies, OAuth tokens, saved logins, credit cards, autofill and history. The report describes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), provides usage examples and an attack scenario demonstrating rapid credential extraction for lateral movement and cloud account takeover, and recommends detections (monitor IElevator calls, headless browser creation, cross-process reads of browser SQLite files) and mitigations (use of external password managers, EDR rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.