logo

Gentoo Pulls the Plug after Getting Pwned

ID: b0610edd-3aa4-5fef-ae88-84c4e241d177

STIX ID: report--b0610edd-3aa4-5fef-ae88-84c4e241d177

Feed Name: Darknet

Threat Score
72/100

Date Published: 2007-09-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major Chromium-based and Firefox browsers on Windows. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL (via Early Bird APC) to use the IElevator COM interface to decrypt the app_bound_encrypted_key, and uses DPAPI/NSS techniques for other browsers; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser) and outputs structured JSON for red-team use while highlighting detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.