Automated Web Auditing and Exploitation Framework
ID: 35f7e0a5-cc0a-5735-b980-d68d9bdd3507
STIX ID: report--35f7e0a5-cc0a-5735-b980-d68d9bdd3507
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool targeting Chrome, Edge, Brave, Opera (including Opera GX), Vivaldi and Firefox; it bypasses App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI and NSS-protected secrets where applicable, and outputs structured JSON. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), is intended for red-team assumed-breach testing but represents a substantial real-world infostealer risk, and the report includes detection opportunities and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
