Incident Response Specification for AI Agents
ID: 2b0ecacc-ead2-53d5-b5bf-9fdab125e365
STIX ID: report--2b0ecacc-ead2-53d5-b5bf-9fdab125e365
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts browser‑stored secrets (saved passwords, cookies, OAuth refresh tokens, credit cards, autofill data and history) from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, employs evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is intended for red‑team/assumed‑breach testing while also representing a high‑risk infostealer capability for real-world abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
