Doppler CLI – Streamlined Secrets Management for DevOps
ID: 4d225d74-9d64-5974-a99e-2734b0bfa01a
STIX ID: report--4d225d74-9d64-5974-a99e-2734b0bfa01a
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass using a DLL injected into a headless Chromium process; Opera/Opera GX/Vivaldi via DPAPI; Firefox via NSS). It extracts cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history to JSON, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and the report outlines attack scenarios, detection opportunities (e.g., IElevator COM use, headless browser instantiation, database reads) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
