logo

Elkeid – A Modern, Scalable HIDS for Cloud-Native Infrastructure

ID: bf02313f-3414-5db7-9c7d-0f0d3d787830

STIX ID: report--bf02313f-3414-5db7-9c7d-0f0d3d787830

Feed Name: Darknet

Threat Score
78/100

Date Published: 2025-04-21

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card details, autofill entries and history from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It implements an App‑Bound Encryption bypass for Chromium by spawning a headless browser and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report provides usage examples, attack scenarios, detection and mitigation guidance, and frames the tool as useful for red teams to assess credential exposure on assumed‑breach developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.