logo

April Commenter of the Month Competition Winner!

ID: e02e8361-f1b0-596e-83db-539f6c51058d

STIX ID: report--e02e8361-f1b0-596e-83db-539f6c51058d

Feed Name: Darknet

Threat Score
80/100

Date Published: 2008-05-08

Date Updated: 2026-05-12

...
...

This report describes DumpBrowserSecrets, a publicly available post-exploitation tool for Windows that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox. It explains how the tool bypasses App-Bound Encryption in modern Chromium builds by spawning a headless browser and injecting a DLL to call the IElevator COM interface, outlines DPAPI/NSS handling for other browsers, lists evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), provides usage and attack scenarios, and discusses detection and mitigation opportunities for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.