logo

Malware Numbers Still Increasing Rapidly

ID: bead32aa-3eba-56ff-b4ab-0e7f25bb5c1c

STIX ID: report--bead32aa-3eba-56ff-b4ab-0e7f25bb5c1c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-12-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major Windows browsers; it implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC, and using the IElevator COM interface to decrypt keys, while using DPAPI and NSS techniques for other browsers. The report covers implementation details, evasion features, example attack scenarios, detection opportunities (process injection, headless browser instantiation, IElevator calls, non-browser reads of browser SQLite DBs) and mitigations such as using dedicated credential managers and EDR controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.