Tracking Users Via the Browser Cache
ID: 6deab39e-f2ba-5aee-8164-8a1bbd74ab16
STIX ID: report--6deab39e-f2ba-5aee-8164-8a1bbd74ab16
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool from Maldev Academy that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers; it implements an App-Bound Encryption bypass for Chrome 127+ by injecting a DLL into a headless Chromium process to use the IElevator COM interface and returns decrypted keys for local decryption, and includes multiple operational evasion features and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
