Open Source Web Application Security Analysis
ID: 3b6da7b7-ca6f-5f14-8439-ae25b427445c
STIX ID: report--3b6da7b7-ca6f-5f14-8439-ae25b427445c
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) by bypassing App‑Bound Encryption and DPAPI—using DLL injection into a headless Chromium process and the IElevator COM interface for key decryption. It outputs structured JSON, includes multiple operational evasion features to reduce EDR detection, and can rapidly expose OAuth tokens and saved credentials enabling cloud account takeover and lateral movement on compromised developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
