November Commenter of the Month Competition Winner!
ID: 43f36a5e-ff82-5a23-9ea0-e736462b486d
STIX ID: report--43f36a5e-ff82-5a23-9ea0-e736462b486d
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill and history) from Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI and NSS encryption models, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and outputs structured JSON suitable for red-team testing or malicious use—enabling rapid cloud account takeover and lateral movement if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
