logo

BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy

ID: e7c8b1da-ce8e-5427-b02a-93c22637abc7

STIX ID: report--e7c8b1da-ce8e-5427-b02a-93c22637abc7

Feed Name: Darknet

Threat Score
75/100

Date Published: 2019-02-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available Windows post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI or NSS-protected secrets as appropriate, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The tool outputs structured JSON of extracted data and is positioned for red-team/assumed-breach use, with recommended detections and mitigations focused on monitoring unexpected headless browser instantiation, IElevator COM calls, and non-browser reads of browser SQLite files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.