Shelling our way up
ID: 0cada1f1-1e45-57fe-8d24-f5cb27023878
STIX ID: report--0cada1f1-1e45-57fe-8d24-f5cb27023878
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based and Gecko browsers on Windows. The tool implements an App‑Bound Encryption bypass (using a headless Chromium process, Early Bird APC DLL injection and the IElevator COM interface) as well as DPAPI and NSS extraction paths for other browsers, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON to facilitate credential reuse; the report also outlines detection points and mitigations such as monitoring IElevator calls, headless browser instantiation, and moving secrets out of browsers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
