Note Chinese Hacker Wicked Rose Heading Antivirus Company Anvisoft
ID: 49c40077-d66b-5046-a968-041f9121d560
STIX ID: report--49c40077-d66b-5046-a968-041f9121d560
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that extracts browser‑stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill, history, and bookmarks) from Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers on Windows. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning headless Chromium, injecting a DLL via Early Bird APC to use the IElevator COM interface, and retrieving decryption keys (DPAPI and NSS handling where applicable), includes multiple operational evasion techniques, and is intended for red‑team assumed‑breach testing but poses a high risk if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
