logo

Information Sharing For Security Assessments

ID: ca6bceaa-8a20-5632-b49d-c5336d0bcaef

STIX ID: report--ca6bceaa-8a20-5632-b49d-c5336d0bcaef

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-06-27

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox to extract saved credentials, cookies, OAuth tokens, credit cards, autofill data and history. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and performing Early Bird APC DLL injection to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON; the report also provides detection opportunities and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.