laptop and data theft protection
ID: 4115fe0c-66aa-564c-945f-912832b399b2
STIX ID: report--4115fe0c-66aa-564c-945f-912832b399b2
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox browsers. It implements a bypass for Chrome's App-Bound Encryption by spawning a headless Chromium instance and injecting a DLL to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and is positioned for red-team/assumed-breach testing while presenting a significant risk if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
