logo

Cambridge Analytica Facebook Data Scandal

ID: d4f95900-c52c-563c-84e1-b43c0ba6d716

STIX ID: report--d4f95900-c52c-563c-84e1-b43c0ba6d716

Feed Name: Darknet

Threat Score
75/100

Date Published: 2018-03-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks) from major Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL (via Early Bird APC) to call the IElevator COM interface to decrypt keys, handles DPAPI and NSS models for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON for red-team or adversary use — making it a high-risk tool for credential theft and cloud session takeover if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.