New Windows XP & Vista Full Take-over Hack with Firewire
ID: 3670b9db-aaac-5487-adcb-492a42a6a034
STIX ID: report--3670b9db-aaac-5487-adcb-492a42a6a034
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) from major browsers by bypassing Chrome's App-Bound Encryption via DLL injection into a headless Chromium process (IElevator COM interface) and handling DPAPI/NSS for other browsers; it outputs structured JSON and includes operational evasion features intended for red-team or adversary use, with guidance on detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
