logo

June 2008 Commenter of the Month Competition Winner!

ID: b3383d11-c0c8-54c2-bdf8-3f352635563d

STIX ID: report--b3383d11-c0c8-54c2-bdf8-3f352635563d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-07-08

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, and uses DPAPI or NSS handling for other browsers; extracted artifacts (cookies, saved logins, OAuth tokens, credit cards, autofill, history) are written to JSON. The README emphasizes red-team use, describes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and provides detection and mitigation recommendations for EDR and policy-level controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.