logo

All You Need To Know About Cross-Site Request Forgery (CSRF)

ID: d261ab66-8f8d-5f06-996f-c6797af04bac

STIX ID: report--d261ab66-8f8d-5f06-996f-c6797af04bac

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-07-27

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers by bypassing App-Bound Encryption (via injecting a DLL into a headless Chromium process and using the IElevator COM interface), or by using DPAPI/NSS decryption for other browsers; the report describes its architecture, evasion techniques, an example attack scenario, detection points, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.