logo

Navy Sys Admin Hacks Into Databases From Aircraft Carrier

ID: c96f640d-9640-5a17-8156-b1a7cfefeac1

STIX ID: report--c96f640d-9640-5a17-8156-b1a7cfefeac1

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-05-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium spawning and DLL injection (Early Bird APC) to access the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON to aid red team or adversary credential theft and SaaS account takeover; the report also outlines detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.