Odysseus Win32 Proxy & Telemachus HTTP Transaction Analysis
ID: 1be82a4c-24b7-5f10-8212-53bf91cfa5c2
STIX ID: report--1be82a4c-24b7-5f10-8212-53bf91cfa5c2
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool intended for red‑team/assumed‑breach use that extracts saved passwords, cookies, OAuth tokens, credit card data, autofill and browsing history from major Chromium‑based and Firefox browsers. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI or NSS keys for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and includes detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
