logo

exe2powershell – Convert EXE to BAT Files

ID: ea123280-3095-5170-bfe5-413fc5161614

STIX ID: report--ea123280-3095-5170-bfe5-413fc5161614

Feed Name: Darknet

Threat Score
75/100

Date Published: 2019-09-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract saved credentials, cookies, OAuth tokens, credit card data, autofill entries, and history. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and outputs structured JSON for red‑team use, with guidance on detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.