The U.S. Department of Defense Hit With $4.9B Lawsuit Over Data Breach
ID: 190abefd-69f1-5f8c-8619-c64e19f1f77e
STIX ID: report--190abefd-69f1-5f8c-8619-c64e19f1f77e
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials (saved logins, cookies, OAuth refresh tokens, credit card data, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless browser and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, includes DPAPI and NSS handling for other browsers, and includes operational evasion features; the report covers usage, attack scenarios, detection strategies, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
