Hackers Crack London Tube Oyster Card
ID: 49aa1324-f144-503a-8eec-3413c124769a
STIX ID: report--49aa1324-f144-503a-8eec-3413c124769a
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation tool that extracts saved passwords, cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI and NSS methods for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool outputs structured JSON and is positioned for red-team assumed-breach use, but the described capabilities enable rapid lateral movement and cloud account takeover if used by malicious actors, with recommended detection opportunities and mitigations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
