logo

xsshunter-express – Self-Hosted Blind XSS Payload Capture and Analysis

ID: dff3afc8-0aaf-51ab-9c48-ed893a4f58d3

STIX ID: report--dff3afc8-0aaf-51ab-9c48-ed893a4f58d3

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-08-11

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests credentials and session data from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + DLL injection (Early Bird APC) to decrypt app_bound_encrypted_key via the IElevator COM interface, includes multiple evasion techniques, outputs structured JSON, and poses a high-risk vector for lateral movement and cloud account takeover if used by adversaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.