logo

Adobe PDF Reader Rewrite To Include Sandbox Feature

ID: c397bcff-8b2e-5ecc-9d8a-23a65995ca6d

STIX ID: report--c397bcff-8b2e-5ecc-9d8a-23a65995ca6d

Feed Name: Darknet

Threat Score
78/100

Date Published: 2010-10-08

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts cookies, saved passwords, OAuth refresh tokens, credit card details, autofill data, and history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It implements a DLL injection + Early Bird APC technique to spawn a headless Chromium process and use the IElevator COM interface to decrypt App‑Bound Encryption keys (Chrome 127+), handles DPAPI and NSS decryption for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is presented for red-team assumed-breach testing while also being relevant to defensive detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.