logo

Sophos Launches FREE Anti-Virus Software For Mac

ID: d31802d6-774b-5f9b-a4ca-db4ff5e6f58f

STIX ID: report--d31802d6-774b-5f9b-a4ca-db4ff5e6f58f

Feed Name: Darknet

Threat Score
72/100

Date Published: 2010-11-02

Date Updated: 2026-05-08

...
...

This report analyzes DumpBrowserSecrets, a publicly available post‑exploitation tool designed to harvest stored credentials and session tokens from major Windows browsers (Chromium-based and Firefox). It details the tool's architecture (an executable and a DLL), techniques to bypass Chrome's App‑Bound Encryption by spawning a headless Chromium and using IElevator COM via Early Bird APC DLL injection, support for DPAPI and NSS decryption, extracted data types (cookies, saved logins, OAuth tokens, credit cards, autofill, history), operational evasion features, recommended detection points, and its use case in red team and assumed‑breach testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.