logo

Researchers Hack Mobile Calls On GSM Network

ID: ac1560f5-ff5f-5b56-a4a6-1fe5ef415a18

STIX ID: report--ac1560f5-ff5f-5b56-a4a6-1fe5ef415a18

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-01-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool for Windows that harvests browser-stored credentials and session tokens from major Chromium and Gecko browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI extraction for some Chromium forks, and NSS decryption for Firefox; outputs are written as structured JSON. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and is intended for red-team/assumed-breach use but enables rapid account takeover and lateral movement if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.