logo

16 New Exploits, 22 Modules & 11 Meterpreter Scripts

ID: be49766c-e125-5ba9-8596-1f9d94ed4f78

STIX ID: report--be49766c-e125-5ba9-8596-1f9d94ed4f78

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-07-16

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool for Windows that harvests browser-stored credentials and session tokens from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses App-Bound Encryption in modern Chromium builds by spawning a headless browser and injecting a DLL to leverage the IElevator COM interface, handles DPAPI and NSS decryption models, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and outputs structured JSON suitable for red team validation of credential exposure and cloud account takeover risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.