logo

Graphical Web Interface for OSSEC WUI AnaLogi v1.1

ID: acd07f36-a180-595c-9b55-4e85331ed78e

STIX ID: report--acd07f36-a180-595c-9b55-4e85331ed78e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-06-19

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt encryption keys, and uses DPAPI or NSS handling for other browsers. The tool includes multiple operational evasion techniques, produces structured JSON output, and can rapidly enable lateral movement and cloud account takeover from a compromised developer workstation, making it a high-risk capability for red teams and real attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.