logo

Super Powered Malware Sandwiches Found In The Wild

ID: ecd18588-d9ae-5009-8065-b65f1dcc8893

STIX ID: report--ecd18588-d9ae-5009-8065-b65f1dcc8893

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-01-25

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is intended for red-team/assumed-breach testing while posing a significant credential-theft risk if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.