Microsoft China Offices Raided By Government
ID: 618268af-f758-5d2e-aec9-da07f81fe44d
STIX ID: report--618268af-f758-5d2e-aec9-da07f81fe44d
Feed Name: Darknet
**DumpBrowserSecrets** is a post-exploitation credential-harvesting tool that extracts saved logins, session cookies, OAuth refresh tokens, credit card numbers, autofill data and browsing history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chrome App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS-protected keys where applicable, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is positioned for red-team assumed-breach testing while representing a realistic capability for credential theft and SaaS account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
