Red Teaming LLMs 2025 – Offensive Security Meets Generative AI
ID: 444bef5b-4150-526b-94cc-ca8ddfde7377
STIX ID: report--444bef5b-4150-526b-94cc-ca8ddfde7377
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool designed to extract browser-stored secrets (saved logins, cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, handles DPAPI and NSS decryption for other browsers, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and includes guidance on detection and mitigation for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
