logo

September Commenter of the Month Competition Winner!

ID: d3486e5d-1ea6-5045-a5dc-e300f76459ea

STIX ID: report--d3486e5d-1ea6-5045-a5dc-e300f76459ea

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-10-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera family/Vivaldi via DPAPI, and Firefox via NSS decryption). It uses Early Bird APC DLL injection into a headless Chromium to leverage the IElevator COM interface, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red team/assumed‑breach testing while enabling rapid cloud account takeover and lateral movement on compromised hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.