Darknet Moving Servers & Upgrades Etc
ID: 3e031432-fb10-5e48-bd94-06a9084ac69c
STIX ID: report--3e031432-fb10-5e48-bd94-06a9084ac69c
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) by bypassing App‑Bound Encryption and DPAPI; it uses headless Chromium process spawning, Early Bird APC DLL injection to call the IElevator COM interface, and other evasion techniques to extract cookies, saved passwords, OAuth refresh tokens, credit card data, autofill entries, and history into structured JSON for use in lateral movement or cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
