logo

Abuse Certificate Transparency Logs For HTTPS Subdomains

ID: b949f785-ea46-525b-8b89-5547aa62608d

STIX ID: report--b949f785-ea46-525b-8b89-5547aa62608d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-10-29

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox. It implements an App‑Bound Encryption bypass for Chromium-based browsers by injecting a DLL into a headless Chromium process and using the IElevator COM interface to decrypt the app_bound_encrypted_key, and handles DPAPI and NSS decryption for other browsers; outputs structured JSON and includes multiple operational evasion techniques, making it a high‑risk capability for lateral movement and cloud account takeover if used by adversaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.