logo

New Argument Switch Attack Bypasses Windows Security Software

ID: f5fde0fe-6cbf-5b1b-a4f0-4092bbb8e2c0

STIX ID: report--f5fde0fe-6cbf-5b1b-a4f0-4092bbb8e2c0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-05-12

Date Updated: 2026-05-12

...
...

**DumpBrowserSecrets** is a publicly released post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It uses headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to obtain encryption keys, outputs structured JSON of recovered secrets, includes multiple evasion techniques, and is intended for red-team assumed‑breach testing but represents a realistic threat vector for cloud/SaaS account takeover and lateral movement if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.