Sniff Passwords From Interface or PCAP File
ID: 3707f372-6135-5e1a-96f0-f1e610f50e5c
STIX ID: report--3707f372-6135-5e1a-96f0-f1e610f50e5c
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history and bookmarks) from major Chromium-based and Firefox browsers. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI and NSS secrets where applicable, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report covers usage, attack scenarios, detection opportunities (unexpected process injection, headless browser instantiation, reads of Login Data/Cookies/Web Data by non-browser processes, IElevator COM calls), and mitigation recommendations such as moving secrets out of browsers and monitoring the IElevator interface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
