Post-Mortem Data Destruction
ID: 0d0d941c-c630-59ed-a942-9f41f06b881d
STIX ID: report--0d0d941c-c630-59ed-a942-9f41f06b881d
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation tool that harvests browser-stored credentials (passwords, cookies, OAuth tokens, credit cards, autofill data, history) from major Windows browsers. It bypasses Chrome’s App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques, and is positioned for red-team assumed-breach testing rather than exfiltration to C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
