logo

Download youtube.com videos?

ID: d61eae9e-d8c5-5d67-98a1-bc0db1307856

STIX ID: report--d61eae9e-d8c5-5d67-98a1-bc0db1307856

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-03-24

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox by using a headless Chromium process, DLL injection (Early Bird APC), and the IElevator COM interface to bypass App‑Bound Encryption (with DPAPI and NSS handling for other browsers). The report documents technical design, evasion features, usage examples for red-team/assumed-breach scenarios, detection opportunities (process injection, IElevator calls, SQLite reads), and mitigation recommendations such as using external credential managers and EDR rules that monitor COM usage and headless browser instantiation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.