New & Free Open-source XSS and SQL Injection Scanner for PHP Programs
ID: 4f3e4cff-71ae-5554-b191-16aabd07fc64
STIX ID: report--4f3e4cff-71ae-5554-b191-16aabd07fc64
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history and bookmarks. It uses an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless process and injecting a DLL via Early Bird APC to call the IElevator COM interface, and it supports DPAPI and NSS decryption for other browsers; the report also documents evasion techniques, example attack scenarios, detection points, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
