logo

New Rootkits Infecting the MBR

ID: b16127f0-4e43-5310-ab00-255639325e11

STIX ID: report--b16127f0-4e43-5310-ab00-255639325e11

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-01-17

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, session cookies, OAuth tokens, credit cards, autofill and history) from major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS models for other browsers, and includes numerous operational evasion features; the tool is positioned for red-team use but can be abused by adversaries to enable account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.