logo

Royal Canadian Mounted Police Arrest Heartbleed Hacker

ID: d5085122-c317-5f9a-9753-e2894b3cc208

STIX ID: report--d5085122-c317-5f9a-9753-e2894b3cc208

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-04-17

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session data from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, retrieves DPAPI or NSS-protected secrets as needed, and outputs structured JSON. The tool includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser) and is intended for red team/assumed-breach testing but materially lowers the cost of browser-based credential theft that can enable lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.