logo

Microsoft Enhanced Mitigation Evaluation Toolkit (EMET)

ID: c98587ab-c21b-577b-9ee0-1cd2004b1106

STIX ID: report--c98587ab-c21b-577b-9ee0-1cd2004b1106

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-06-01

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a public post-exploitation credential-harvesting tool that extracts browser-stored secrets from Chrome/Edge/Brave (via an App-Bound Encryption IElevator COM bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The report details its executable+DLL architecture, Early Bird APC DLL injection into headless Chromium to decrypt app_bound_encrypted_key, supported data types (passwords, cookies, OAuth tokens, credit cards, autofill, history), operational evasion features, an example attack scenario, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.