logo

Microsoft Data Harvesting Backported To Windows 7 & 8

ID: bb3b4926-74df-5801-86d0-b93a372615f4

STIX ID: report--bb3b4926-74df-5801-86d0-b93a372615f4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-09-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser‑stored credentials (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from Chromium‑based browsers and Firefox by bypassing App‑Bound Encryption (via spawning a headless browser and DLL injection using Early Bird APC to call the IElevator COM interface) or by extracting DPAPI/NSS keys; the report documents its capabilities, evasion techniques, usage, detection opportunities, and mitigation advice for red teams and defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.