logo

Google Chrome Marking ALL Non-HTTPS Sites Insecure July 2018

ID: bed6ce30-57cf-5663-9c53-24e33583b733

STIX ID: report--bed6ce30-57cf-5663-9c53-24e33583b733

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-02-09

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from major Chromium-based and Firefox browsers on Windows. It includes an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and performing Early Bird APC DLL injection to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, and implements operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The tool outputs structured JSON and is intended for red-team/assumed-breach testing but represents a high-impact capability if abused by adversaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.