WiFi-Dumper – Dump WiFi Profiles and Cleartext Passwords
ID: 601244c4-96a2-54f0-a9bd-fb3e7df86843
STIX ID: report--601244c4-96a2-54f0-a9bd-fb3e7df86843
Feed Name: Darknet
DumpBrowserSecrets is a public, precompiled Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium and Gecko browsers by using a DLL-injection-based IElevator COM bypass for App-Bound Encryption (Chrome/Edge/Brave), DPAPI extraction for Opera/Vivaldi, and NSS decryption for Firefox; it outputs structured JSON, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, file-handle duplication), and is positioned for red-team assumed-breach testing but presents a high-risk capability for real-world credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
