logo

July Commenter of the Month Competition Winner 2008!

ID: fd6cb8a9-4e2e-5f45-9ad9-410a430aa89c

STIX ID: report--fd6cb8a9-4e2e-5f45-9ad9-410a430aa89c

Feed Name: Darknet

Threat Score
72/100

Date Published: 2008-08-05

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based browsers (Chrome, Edge, Brave) by bypassing App-Bound Encryption via Early Bird APC DLL injection into a headless Chromium process and using the IElevator COM interface, and handles Opera/Vivaldi via DPAPI and Firefox via NSS. It extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill, history and bookmarks into JSON, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), is distributed as precompiled binaries, and is positioned as a red-team tool for testing endpoint controls and SaaS credential exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.