logo

Pingcastle – Active Directory Security Assessment Tool

ID: f3138b54-c15f-54c5-b60e-ac9683b6648b

STIX ID: report--f3138b54-c15f-54c5-b60e-ac9683b6648b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2020-05-18

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool for Windows that targets Chromium-based browsers (Chrome, Edge, Brave, etc.) and Firefox to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. The tool bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON for red-team use, and poses a high-risk credential-theft vector for compromised developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.