Virtual Host Scanner With Alias & Catch-All Detection
ID: 36a97dcb-1e23-56c7-8073-a8d77eb3e943
STIX ID: report--36a97dcb-1e23-56c7-8073-a8d77eb3e943
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data and browsing history from Chromium-based and Firefox browsers by bypassing App-Bound Encryption (via IElevator COM) and DPAPI/NSS protections. The report details the tool's architecture (an executable plus an injected DLL using Early Bird APC injection), supported browsers, evasion features, example attack scenarios enabling cloud account takeover, and detection/mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
