logo

Odysseus Win32 Proxy & Telemachus HTTP Transaction Analysis

ID: 1be82a4c-24b7-5f10-8212-53bf91cfa5c2

STIX ID: report--1be82a4c-24b7-5f10-8212-53bf91cfa5c2

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-02-01

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool intended for red‑team/assumed‑breach use that extracts saved passwords, cookies, OAuth tokens, credit card data, autofill and browsing history from major Chromium‑based and Firefox browsers. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves DPAPI or NSS keys for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and includes detection and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.