logo

Active Web Application Security Reconnaissance Tool

ID: 9574f71d-fd52-5f53-b40a-fc340140f9df

STIX ID: report--9574f71d-fd52-5f53-b40a-fc340140f9df

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-06-15

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential harvesting tool (available as precompiled binaries) that extracts browser‑stored secrets — saved passwords, cookies, OAuth refresh tokens, credit cards, autofill entries and history — from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox. It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and recover encryption keys, includes DPAPI and NSS handling for other browsers, and incorporates operational evasion features; the report covers usage, detection opportunities, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.