logo

Taof 0.1 Network Protocol Fuzzer Released

ID: a15750ee-737a-54c6-a737-f6a06a4093cf

STIX ID: report--a15750ee-737a-54c6-a737-f6a06a4093cf

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-11-08

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI for some Chromium forks and NSS decryption for Firefox, outputs structured JSON, and includes multiple operational evasion features; the report covers usage, attack scenarios, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.