logo

BobCat SQL Injection Tool based on Data Thief

ID: bdb8f5e0-3fc2-50c7-ba2a-7c91316dc557

STIX ID: report--bdb8f5e0-3fc2-50c7-ba2a-7c91316dc557

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-10-27

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by bypassing App‑Bound Encryption (via a headless browser, DLL injection, and the IElevator COM interface) or using DPAPI/NSS decryption for other browsers. The report describes supported browsers and extracted data types (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history), operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), typical attack scenarios, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.