logo

Hackers Penetrate Apache.org In Direct Targeted Attack

ID: bc3ba276-4fab-5349-b14b-b7a2004111d3

STIX ID: report--bc3ba276-4fab-5349-b14b-b7a2004111d3

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-04-14

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key; DPAPI and NSS decryption are used where applicable. The report covers operational features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), an attack scenario showing rapid credential extraction and cloud account replay, and detection/mitigation recommendations such as monitoring IElevator calls, headless browser instantiation, and restricting browser‑stored secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.