logo

Brittany Murphy Dies & Scareware Scammers Strike

ID: ef470590-bdf9-585e-b5f2-b5be20c89333

STIX ID: report--ef470590-bdf9-585e-b5f2-b5be20c89333

Feed Name: Darknet

Threat Score
78/100

Date Published: 2009-12-22

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via an App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It combines a compiled executable and a DLL injected into a headless Chromium process to decrypt app-bound keys, extracts cookies, saved logins, OAuth refresh tokens, credit card data and history into JSON, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report outlines attack scenarios, detection opportunities (process injection, IElevator COM calls, reads of Login Data/Cookies/Web Data by non-browser processes) and mitigations such as using external credential managers and EDR monitoring of the IElevator interface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.