logo

Mask Against TCP/IP Fingerprinting for Windows

ID: a6eea5aa-3482-5d5b-96cd-d42721e32fc9

STIX ID: report--a6eea5aa-3482-5d5b-96cd-d42721e32fc9

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-17

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera (including Opera GX), Vivaldi, and Firefox by using techniques such as Early Bird APC DLL injection into a headless Chromium process to leverage the IElevator COM interface and bypass App-Bound Encryption, plus DPAPI and NSS handling for other browsers; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red team or adversary use, enabling rapid credential-driven lateral movement and cloud account takeover if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.