Merry Xmas From Darknet
ID: 2ec634da-407f-5d50-8f87-f578faf8b215
STIX ID: report--2ec634da-407f-5d50-8f87-f578faf8b215
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-extraction tool that targets Chrome, Edge, Brave (App-Bound Encryption bypass via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to harvest saved passwords, session cookies, OAuth tokens, credit cards, autofill data and history. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC) to decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red-team tool useful for assessing realistic credential exposure and testing EDR controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
