Microsoft’s Live OneCare the WORST Anti-Virus Solution
ID: 332ce9ea-4db8-5020-9cb9-779b3b84f4fc
STIX ID: report--332ce9ea-4db8-5020-9cb9-779b3b84f4fc
Feed Name: Darknet
DumpBrowserSecrets is a publicly available Windows post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill and history) from major Chromium-based browsers and Firefox; it implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, and handles DPAPI- and NSS-encrypted stores for other browsers. The report details the tool's architecture (executable + DLL), supported browsers, extracted data types, operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), an example attack scenario, red team relevance, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
