logo

Website Directory Scanner For Files & Structure

ID: e8d16270-e501-5d41-8d4a-24852fcb19aa

STIX ID: report--e8d16270-e501-5d41-8d4a-24852fcb19aa

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-10-28

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (targeting Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption) that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history into structured JSON. It uses headless Chromium instantiation, Early Bird APC DLL injection and the IElevator COM interface to decrypt app_bound_encrypted_key on modern Chromium builds, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication, custom SQLite parsing), and is presented as a red team tool useful for assessing the blast radius of compromised developer endpoints while also representing a high‑impact capability if adopted by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.