logo

Wazuh – Open Source Security Platform for Threat Detection, Visibility & Compliance

ID: dfce6c2f-30eb-5ee1-9fb6-3daf197ef015

STIX ID: report--dfce6c2f-30eb-5ee1-9fb6-3daf197ef015

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-05-16

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials and session artifacts across Chromium- and Gecko-based browsers on Windows. It implements an App‑Bound Encryption bypass for modern Chromium builds by spawning a headless browser and injecting a DLL via Early Bird APC to call the IElevator COM interface, plus DPAPI and NSS handling for other browsers; outputs structured JSON and includes evasion techniques making it relevant for red teams and threat actors testing or abusing browser credential surfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.