logo

Facebook Attachment Uploader Owned By A Space

ID: 9fbfd027-5ce7-5925-b01c-a5d46215d2e1

STIX ID: report--9fbfd027-5ce7-5925-b01c-a5d46215d2e1

Feed Name: Darknet

Threat Score
70/100

Date Published: 2011-10-27

Date Updated: 2026-05-12

...
...

This report analyzes DumpBrowserSecrets, a Windows post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) from Chromium-based and Firefox browsers by bypassing App-Bound Encryption and DPAPI/NSS protections; it explains the executable+DLL architecture, Early Bird APC DLL injection into a headless Chromium process to use the IElevator COM interface, evasion techniques, use-cases for red teams, and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.