logo

Fast and Full-Featured SSL Configuration Scanner

ID: 9f972c66-e963-5860-b1a5-1ee806521546

STIX ID: report--9f972c66-e963-5860-b1a5-1ee806521546

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-12-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Chromium-based and Firefox browsers. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, includes DPAPI and NSS handling for other browsers, and implements multiple operational evasion techniques; the report covers usage, detection opportunities, and mitigations for red team and defensive testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.