logo

Google Desktop Privacy? OR Lack Of..

ID: e46f23e4-754f-5d86-9bf4-15b22d1d03c0

STIX ID: report--e46f23e4-754f-5d86-9bf4-15b22d1d03c0

Feed Name: Darknet

Threat Score
70/100

Date Published: 2006-02-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chrome/Edge/Brave (using an App‑Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses a headless Chromium spawn and Early Bird APC DLL injection to invoke the IElevator COM interface to decrypt app_bound_encrypted_key, includes multiple runtime evasion techniques, outputs structured JSON for red team use, and outlines detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.