logo

‘Free’ USB Drives Defeat Company Security

ID: f6a0397d-4a9c-515b-ad19-c7402ad7c429

STIX ID: report--f6a0397d-4a9c-515b-ad19-c7402ad7c429

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-07-06

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data and history) from major Windows browsers. It implements an App‑Bound Encryption bypass for Chromium (injecting a DLL into a headless Chromium process via Early Bird APC to use the IElevator COM interface), handles DPAPI and NSS cases for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON — enabling rapid credential theft and potential cloud account takeover if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.