CMS Identification & Information Gathering Tool
ID: 1e3d4ce6-5ced-5f15-bc7f-23f2fb4c9c5f
STIX ID: report--1e3d4ce6-5ced-5f15-bc7f-23f2fb4c9c5f
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox by decrypting browser vaults (including an IElevator COM-based bypass of Chrome's App‑Bound Encryption). It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC) to retrieve encryption keys, parses on-disk SQLite/JSON stores, and writes structured JSON output; operational evasion features and use cases for lateral movement and cloud account takeover are described along with detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
