Source Code & Software Security Analysis with BogoSec
ID: 4dc2738c-1db0-5243-b502-e4dc141e069e
STIX ID: report--4dc2738c-1db0-5243-b502-e4dc141e069e
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool for Windows that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill entries and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to leverage the IElevator COM interface, parses on-disk SQLite/JSON stores, and writes structured JSON output; the report covers capabilities, usage, attack scenarios, evasion techniques, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
