logo

Core Security to Expand Market with Mark Hatton

ID: b7eab951-5e1a-5f64-a4d8-a0eba3ae6d4d

STIX ID: report--b7eab951-5e1a-5f64-a4d8-a0eba3ae6d4d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-03-19

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts passwords, cookies, OAuth refresh tokens, credit card details, autofill data and browsing history from Chromium‑based (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, outputs structured JSON, and includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) to reduce EDR detection; the report also describes detection opportunities and mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.