logo

Framework For Implementing SCAP (Security Content Automation Protocol)

ID: ae5d3d64-c8a5-5027-ad69-251b04d685d0

STIX ID: report--ae5d3d64-c8a5-5027-ad69-251b04d685d0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-06-21

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool (with an executable and DLL) that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Vivaldi/Opera GX (DPAPI), and Firefox (NSS) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It uses headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to decrypt app_bound_encrypted_key for modern Chromium builds, includes multiple operational evasion features, outputs structured JSON for red‑team use, and is discussed alongside detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.