logo

UFO ‘Hacker’ Gary McKinnon Reveals What He Found

ID: a2cb1961-fe55-5c14-b554-22d5717b8a82

STIX ID: report--a2cb1961-fe55-5c14-b554-22d5717b8a82

Feed Name: Darknet

Threat Score
74/100

Date Published: 2006-06-25

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest browser-stored credentials and tokens from Windows hosts across Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and outputs structured JSON containing cookies, OAuth refresh tokens, saved logins, autofill data, and history — enabling rapid lateral movement or cloud account takeover if run on a compromised developer workstation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.