logo

US Investigators Pinpoint Author Of Google Attack Code

ID: c5f264cc-5116-5852-93c5-28f56bc23646

STIX ID: report--c5f264cc-5116-5852-93c5-28f56bc23646

Feed Name: Darknet

Threat Score
72/100

Date Published: 2010-02-22

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by injecting a DLL into a headless browser process to call the IElevator COM interface, supports DPAPI and NSS decryption methods for other browsers, includes operational evasion tricks (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and outputs structured JSON useful for red team or malicious reuse; the report also describes detection points and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.