logo

Router/Switch Default Password List Updated

ID: 98f9a890-7cbd-5edd-bf2b-00c05d682aaa

STIX ID: report--98f9a890-7cbd-5edd-bf2b-00c05d682aaa

Feed Name: Darknet

Threat Score
70/100

Date Published: 2007-01-25

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests credentials and session tokens from major Chromium- and Gecko-based browsers by using techniques including headless Chromium spawning, Early Bird APC DLL injection, and IElevator COM usage to bypass App-Bound Encryption; it also handles DPAPI and NSS-protected stores. The tool outputs structured JSON, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), and is intended for red-team assumed-breach exercises but presents a high-risk capability for credential theft and cloud account takeover if used maliciously. Detection focuses on abnormal headless browser instantiation, process injection into browser processes, IElevator calls from non-browser contexts, and unauthorized reads of browser SQLite files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.