logo

Merry Christmas 2012 From Darknet

ID: 97649d2c-19ff-5f88-9691-594a7154cf99

STIX ID: report--97649d2c-19ff-5f88-9691-594a7154cf99

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-12-24

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and tokens from Chromium- and Gecko-based browsers. It implements an App-Bound Encryption bypass for modern Chromium builds by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt the app_bound_encrypted_key, and then parses and decrypts browser SQLite/JSON stores; it also handles DPAPI and NSS models for other browsers, outputs structured JSON, and includes multiple evasion techniques aimed at EDR and forensic detection — making it a high-impact capability for lateral movement and SaaS account takeover in assumed-breach engagements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.