logo

Detect & Remove Malicious Code/Web Pages Viruses From Your Linux/Unix Server

ID: ce272ab8-80f4-5286-8fe6-0a66c382da33

STIX ID: report--ce272ab8-80f4-5286-8fe6-0a66c382da33

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-05-11

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. The tool implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and returning decrypted keys to a local executable; it also handles DPAPI and NSS decryption models, includes multiple evasion techniques, and outputs results as structured JSON for red-team use and testing of endpoint controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.