SIFT Web Method Search Tool
ID: 02001ee5-6c5a-5e42-847a-f96d4b80077b
STIX ID: report--02001ee5-6c5a-5e42-847a-f96d4b80077b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, and handles DPAPI and NSS decryption for other browsers; output is structured JSON. The report covers usage, operational evasion features, an attack scenario demonstrating cloud account takeover potential, and detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
