logo

OWASP (Open Web Application Security Project) Testing Guide v3 Released

ID: fb909db9-005e-55f5-baa9-61f9065e304e

STIX ID: report--fb909db9-005e-55f5-baa9-61f9065e304e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-01-12

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored credentials and session data (saved passwords, cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt keys, uses DPAPI/NSS for other browsers, includes operational evasion features, and outputs structured JSON; the report also covers detection signals and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.