Open Source Vulnerability Management System
ID: 3669d9f8-0667-51ba-a8ca-00f03b053e87
STIX ID: report--3669d9f8-0667-51ba-a8ca-00f03b053e87
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based browsers (Chrome, Edge, Brave, Opera-derived browsers) and Firefox by bypassing App-Bound Encryption, DPAPI, and NSS protections; it injects a DLL into a headless Chromium process (Early Bird APC) to call the IElevator COM interface, retrieves decryption keys, parses on-disk SQLite/JSON stores, and outputs structured JSON. The report details supported browsers and data types, operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), a realistic attack scenario, and recommended detection/mitigation approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
