ARP Handler Detect and Block ARP Poisoning/Spoofing
ID: 024c424e-9c06-5b92-b621-c6a5e3897dd0
STIX ID: report--024c424e-9c06-5b92-b621-c6a5e3897dd0
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and using DLL injection plus the IElevator COM interface to decrypt keys, includes DPAPI and NSS handling for other browsers, and implements multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The tool is positioned for red-team/assumed-breach testing but represents a high-risk capability for lateral movement and cloud account takeover if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
