GitPhish – OAuth Device Code Phishing for GitHub Repos, Secrets, and CI/CD
ID: 0d353190-5fda-5a05-8427-3f07176d2e0b
STIX ID: report--0d353190-5fda-5a05-8427-3f07176d2e0b
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential-harvesting tool (Windows executable + DLL) that targets Chromium- and Gecko-based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave via spawning a headless Chromium process, injecting a DLL with Early Bird APC to access the IElevator COM interface, and decrypts browser vaults locally; Opera/Vivaldi and Firefox are handled via DPAPI or NSS methods. The report covers extraction output, evasion features, operational usage, detection opportunities, and mitigation advice for red-team and defensive testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
