logo

Understanding the Deep Web, Dark Web, and Darknet (2025 Guide)

ID: eeb5e5be-d246-5a73-96f0-bd6dea805c58

STIX ID: report--eeb5e5be-d246-5a73-96f0-bd6dea805c58

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-04-30

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome/Brave/Edge via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS) to extract cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks. It spawns a headless Chromium process and injects a DLL using Early Bird APC to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red-team/assumed‑breach tool for assessing SaaS and browser credential exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.