Collar Bomber Gets Owned By Word Metadata & USB Drive
ID: 298212e7-1aa4-5fb2-850a-beb42e05f05c
STIX ID: report--298212e7-1aa4-5fb2-850a-beb42e05f05c
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It uses a compiled executable and a DLL to bypass App-Bound Encryption (via spawning a headless Chromium process and IElevator COM calls using Early Bird APC injection) or DPAPI/NSS decryption as appropriate, extracts cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history, includes evasion techniques to reduce EDR detection, and outputs structured JSON for red team or adversary use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
