Without OneCare in the World.
ID: 2a6c98ad-b3ce-5038-a441-f40b9d5e39ed
STIX ID: report--2a6c98ad-b3ce-5038-a441-f40b9d5e39ed
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post-exploitation tool for Windows that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from major browsers by using techniques like Early Bird APC DLL injection into a headless Chromium process to leverage the IElevator COM interface and decrypt App-Bound Encryption keys, plus DPAPI and NSS handling for other browsers; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and is intended for red-team assumed-breach testing but materially increases risk if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
