U.S. State Department Hacked
ID: 29929625-3fcb-5909-b10e-fcac6ae5817b
STIX ID: report--29929625-3fcb-5909-b10e-fcac6ae5817b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool (from Maldev Academy) that extracts browser‑stored secrets across Chromium and Gecko browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, handles DPAPI and NSS models for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The tool outputs structured JSON and is positioned for red team/assumed‑breach use, but the described capabilities also represent a realistic offensive capability for credential theft, session replay, and cloud account takeover unless detected or mitigated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
