GPU Powered High Performance Multihash Brute Forcer
ID: 5c096aac-b70c-5321-9e63-d312d198d9c0
STIX ID: report--5c096aac-b70c-5321-9e63-d312d198d9c0
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption) as well as Opera, Vivaldi (DPAPI) and Firefox (NSS). It uses headless Chromium instantiation and Early Bird APC DLL injection to leverage the IElevator COM interface to decrypt app_bound_encrypted_key, extracts cookies, saved logins, OAuth refresh tokens, credit card and autofill data from on‑disk SQLite/JSON stores, and includes multiple operational evasion features; the report covers technical operation, example attack scenarios, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
