logo

1 Million Accounts Leaked From Banks, Government Agencies & Consultancy Firms

ID: feff3b65-5957-508a-a6c0-1bb9fe8d5d2f

STIX ID: report--feff3b65-5957-508a-a6c0-1bb9fe8d5d2f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-08-01

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card details, autofill data, and history from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and implements multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool is presented as a red‑team utility that outputs JSON, can complete extraction in under 30 seconds, and poses a high risk for lateral movement and cloud session takeover if used on developer or authenticated endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.