logo

Easy-to-use Software Library For Encryption

ID: a3fe9838-be26-54ae-8b18-770c0d79878b

STIX ID: report--a3fe9838-be26-54ae-8b18-770c0d79878b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-03-05

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials (cookies, logins, OAuth refresh tokens, credit cards, autofill and history) from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox. It implements an App-Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI or NSS-protected keys as needed, and outputs structured JSON; the README documents usage, evasion features, attack scenarios, detection indicators, and mitigation recommendations for red-team and defensive testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.