German Police Creating Law Enforcement Trojan
ID: 64476ce3-51ce-59c1-b86b-4830a017ee4c
STIX ID: report--64476ce3-51ce-59c1-b86b-4830a017ee4c
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session artifacts from major Chromium-based and Firefox browsers on Windows. It implements a sophisticated App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve the decryption key; it also handles DPAPI and NSS-encrypted stores for other browsers. The tool outputs structured JSON, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is positioned for red-team/assumed-breach use but represents a high-risk capability for real-world credential theft and cloud account takeover if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
