logo

User Mode Program Can Disable User Access Control

ID: c1fcd6fd-d6dd-512c-8cf5-335b750c2c08

STIX ID: report--c1fcd6fd-d6dd-512c-8cf5-335b750c2c08

Feed Name: Darknet

Threat Score
70/100

Date Published: 2009-02-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation browser credential harvesting tool that targets Chrome/Edge/Brave (via an IElevator App‑Bound Encryption bypass using Early Bird APC DLL injection), Opera/Vivaldi (DPAPI), and Firefox (NSS) to extract saved passwords, cookies, OAuth refresh tokens, credit card data, autofill, and history into JSON. The report documents implementation details, evasion techniques, supported browsers, example attacker workflows, detection opportunities, and red‑team relevance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.