PowerShell Runspace Portable Post Exploitation Tool
ID: 3f94eb9e-7768-5160-b9d2-661d9c8e6e67
STIX ID: report--3f94eb9e-7768-5160-b9d2-661d9c8e6e67
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based and Firefox browsers on Windows, using a compiled executable and a DLL injected into a headless Chromium process to bypass App-Bound Encryption via the IElevator COM interface (and handling DPAPI/NSS where applicable). It extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill and history into JSON, includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parsing), and is positioned for red-team assumed-breach testing while representing a significant real-world risk if used maliciously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
