Commenter of the Month Competition
ID: 0d1c15e8-9c56-53be-8ba9-5fcc2a21b123
STIX ID: report--0d1c15e8-9c56-53be-8ba9-5fcc2a21b123
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from major browsers (Chrome, Edge, Brave, Opera/Opera GX, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key, handles DPAPI and NSS models for other browsers, outputs structured JSON, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report details usage, attack scenarios, detection opportunities, and mitigations for enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
