Court Orders Seizure Of PS3 Hacker's Computers
ID: 27e062cb-50c7-5660-901f-1dedcd316b08
STIX ID: report--27e062cb-50c7-5660-901f-1dedcd316b08
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process, performing Early Bird APC DLL injection to use the IElevator COM interface to decrypt app_bound_encrypted_key, and parses on-disk SQLite/JSON stores; Opera-family browsers use DPAPI retrieval and Firefox uses NSS decryption. The report covers usage, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), an attack scenario demonstrating rapid credential extraction and replay, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
