logo

Malware Pushers Abuse Firefox Warning Page

ID: c52e2263-3e29-5c91-adbe-c1826b693d55

STIX ID: report--c52e2263-3e29-5c91-adbe-c1826b693d55

Feed Name: Darknet

Threat Score
70/100

Date Published: 2010-10-21

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium‑based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI extraction for Opera/Vivaldi, and NSS decryption for Firefox, includes multiple operational evasion features (string obfuscation, API hashing, Early Bird APC injection, PPID/argument spoofing, custom SQLite parser), and writes structured JSON output to facilitate credential replay and lateral movement; the report also outlines detection and mitigation opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.