logo

Google has no license for China service

ID: eab523aa-1359-537d-ae38-35c645360c24

STIX ID: report--eab523aa-1359-537d-ae38-35c645360c24

Feed Name: Darknet

Threat Score
78/100

Date Published: 2006-02-21

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by using DLL injection into a headless Chromium process to bypass App‑Bound Encryption via the IElevator COM interface, and by handling DPAPI/NSS for other browsers; it outputs structured JSON and includes evasion features to reduce EDR detection. The report covers supported data types (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history), usage examples, attack scenarios demonstrating rapid credential extraction for lateral movement and cloud account takeover, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.