logo

Build, Host & Share Vulnerable Web Application Code

ID: e4a5a61c-67e9-527d-9648-e26e75813e95

STIX ID: report--e4a5a61c-67e9-527d-9648-e26e75813e95

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-11-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool for Windows that extracts passwords, cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI or NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), writes structured JSON output, and is positioned as a red team utility while representing a real offensive capability that defenders should detect and mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.