British Workers Love to Snoop Salary Info, Personal Notes & Colleagues Data
ID: 48a33393-0f67-5e53-977e-136d3828292b
STIX ID: report--48a33393-0f67-5e53-977e-136d3828292b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome/Chromium-based browsers, Opera-family browsers, and Firefox. It implements an App-Bound Encryption bypass for Chrome 127+ by injecting a DLL into a headless Chromium process to call the IElevator COM interface, supports DPAPI and NSS decryption paths, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parser), outputs structured JSON, and is positioned for red-team use but presents a significant risk if used by adversaries for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
