US Government Cyber Security Still Inadequate
ID: 07ed05e9-95df-501f-8833-8d9bce8c7645
STIX ID: report--07ed05e9-95df-501f-8833-8d9bce8c7645
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based browsers (bypassing Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process and using the IElevator COM interface), DPAPI-based browsers (Opera, Vivaldi), and Firefox (NSS). The report documents extracted data types (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history), operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, file-handle duplication, custom SQLite parser), usage examples, detection opportunities, and red-team relevance for assumed-breach engagements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
