logo

Tunisia Running Country Wide Facebook, Gmail & Yahoo! Password Capture

ID: bc2b105c-c92a-5cbe-9325-8d2381ac8d59

STIX ID: report--bc2b105c-c92a-5cbe-9325-8d2381ac8d59

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-02-10

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks) across major Chromium-based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by injecting a DLL into a headless Chromium process to use the IElevator COM interface to decrypt keys, uses DPAPI extraction for Opera/Vivaldi variants, and NSS decryption for Firefox. The tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is framed for red-team engagements while also representing a high-impact capability for credential theft and cloud account takeover if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.