logo

Privileged Account Threat Detection Tool

ID: e830cd76-1d1a-55a9-b232-a2ddae4df9cd

STIX ID: report--e830cd76-1d1a-55a9-b232-a2ddae4df9cd

Feed Name: Darknet

Threat Score
80/100

Date Published: 2020-03-31

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool designed to harvest browser-stored secrets (cookies, saved logins, OAuth tokens, credit cards, autofill data, history, and bookmarks) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox; it bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and returns decrypted keys to an executable that parses and decrypts on-disk SQLite/JSON stores. The report details implementation, supported browsers and encryption models (App-Bound V20, DPAPI V10, NSS), operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), an example attack scenario, detection opportunities, and mitigation recommendations for enterprise defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.