Hackers Steal U.S. Government Corporate Data from PCs
ID: 2d3a781d-0a06-5bf8-88f6-f7159efd7bc2
STIX ID: report--2d3a781d-0a06-5bf8-88f6-f7159efd7bc2
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, history, and bookmarks) across Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by injecting a DLL into a headless Chromium process via Early Bird APC to call the IElevator COM interface, handles DPAPI for other Chromium forks, uses NSS decryption for Firefox, includes EDR-evasion features, and outputs structured JSON for red-team or adversary use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
