SQL Injection Tool for MS-SQL Released for Download
ID: 3f7be3dd-e9b6-55fe-bd15-81351659658e
STIX ID: report--3f7be3dd-e9b6-55fe-bd15-81351659658e
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens across major Chromium‑based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to call the IElevator COM interface (using Early Bird APC injection), retrieves decryption keys (or DPAPI/NSS keys for other browsers), and parses on‑disk browser databases to output structured JSON. The report covers supported browsers and data types, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), an attack scenario demonstrating rapid credential extraction for lateral movement and cloud account takeover, and detection/mitigation guidance for EDR and policy controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
