The Next Big Thing? Fortify Readiness Scorecard
ID: 2919b1a5-c243-5cf6-a09f-bdeb2c7475ff
STIX ID: report--2919b1a5-c243-5cf6-a09f-bdeb2c7475ff
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data and history from major Chromium‑based and Firefox browsers on Windows. The tool bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (using Early Bird APC) to call the IElevator COM interface, handles DPAPI for Opera/Vivaldi and NSS for Firefox, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), and is intended for red‑team testing but presents a realistic risk for lateral movement and cloud account takeover if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
