logo

EyeWitness – A Rapid Web Application Triage Tool

ID: b4908414-9cd7-5e78-bbe6-07a5aef1c8cd

STIX ID: report--b4908414-9cd7-5e78-bbe6-07a5aef1c8cd

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-03-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session data (passwords, cookies, OAuth refresh tokens, credit cards, autofill, history) from Chrome/Edge/Brave (App‑Bound Encryption), Opera/Vivaldi (DPAPI) and Firefox (NSS). The report details a Chrome 127+ App‑Bound Encryption bypass using a headless Chromium process with Early Bird APC DLL injection and the IElevator COM interface, describes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), provides usage examples and red-team context, and outlines detection and mitigation opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.