logo

Google Chrome To Protect Users Against Malicious Executables

ID: e4d56db4-2868-5380-a0ec-fdf6eee70877

STIX ID: report--e4d56db4-2868-5380-a0ec-fdf6eee70877

Feed Name: Darknet

Threat Score
72/100

Date Published: 2011-04-06

Date Updated: 2026-05-18

...
...

**Executive Summary:** DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Vivaldi (DPAPI), and Firefox (NSS) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history; it implements a headless Chromium DLL injection (Early Bird APC + IElevator COM interface) to bypass App‑Bound Encryption, includes multiple evasion features, and is presented with usage examples, detection guidance, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.