Absinthe Blind SQL Injection Tool/Software
ID: 49ce34d3-e1bc-5b9d-8307-e3efbef5875f
STIX ID: report--49ce34d3-e1bc-5b9d-8307-e3efbef5875f
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass; Opera/Vivaldi via DPAPI; Firefox via NSS). The tool uses headless Chromium spawning with early-bird APC DLL injection and the IElevator COM interface to decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team testing but could be repurposed by adversaries; detection and mitigation strategies are discussed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
