Open Source Windows File Encryption Software
ID: 3f80cf76-76c8-54bd-b397-89ac8c62d72b
STIX ID: report--3f80cf76-76c8-54bd-b397-89ac8c62d72b
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and tokens from Chrome, Edge, Brave (via an App‑Bound Encryption bypass using a headless Chromium process and IElevator COM interface), Opera/ Vivaldi (DPAPI), and Firefox (NSS). It injects a DLL into a Chromium context to decrypt app_bound_encrypted_key, parses on-disk SQLite/JSON stores, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team assumed-breach testing but represents a real enterprise credential-theft and cloud account takeover risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
