Sandbox Your Browser / Software / Programs In Windows
ID: 6e63978d-2b3a-5fae-ac12-58402e7442f4
STIX ID: report--6e63978d-2b3a-5fae-ac12-58402e7442f4
Feed Name: Darknet
Threat Score
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored credentials and session data across Chromium‑based and Gecko‑based browsers by bypassing App‑Bound Encryption (via IElevator COM invoked from an injected DLL) and handling DPAPI/NSS encryption models; it outputs structured JSON and includes operational evasion features to reduce EDR detection, making it useful for red teams and a credible risk if adopted by malicious operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
