logo

DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass

ID: e4aa47e2-b063-576e-8ec9-e4ae275a284c

STIX ID: report--e4aa47e2-b063-576e-8ec9-e4ae275a284c

Feed Name: Darknet

Threat Score
70/100

Date Published: 2026-03-09

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based and Firefox browsers on Windows by using techniques such as headless Chromium spawning, Early Bird APC DLL injection, and an IElevator COM bypass to defeat App‑Bound Encryption; it extracts cookies, saved logins, OAuth refresh tokens, credit cards, and history into JSON, includes evasion features to reduce EDR detection, and is positioned for red‑team/assumed‑breach testing but represents a credible high‑risk capability if used by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.