logo

Exploits For Popular SCADA Programs Made Public

ID: 9a741d54-d34a-568f-b4e7-843d4310b609

STIX ID: report--9a741d54-d34a-568f-b4e7-843d4310b609

Feed Name: Darknet

Threat Score
70/100

Date Published: 2011-03-23

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a pre-compiled Windows post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process and using the IElevator COM interface to decrypt keys, uses DPAPI or NSS handling for other browsers, and outputs structured JSON of extracted cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history. The tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) intended to reduce EDR detection and is positioned for red-team/assumed-breach testing but also represents a real credential-theft capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.