logo

The Ultimate Utility to Control Facebook Accounts

ID: a9817d6b-c4de-5f71-90e4-cb0c9ed8d98d

STIX ID: report--a9817d6b-c4de-5f71-90e4-cb0c9ed8d98d

Feed Name: Darknet

Threat Score
78/100

Date Published: 2009-05-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens across Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (using Early Bird APC injection), retrieves DPAPI or NSS keys where applicable, parses on-disk SQLite/JSON stores, and outputs structured JSON. The README documents supported data types (passwords, cookies, OAuth tokens, credit cards, autofill, history), operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), recommended detection points (injection into Chromium, IElevator calls, non-browser reads of Login Data/Cookies/Web Data), and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.