In 2016 Your Wireless Keyboard Security Still SUCKS
ID: 6fabf53f-e3d2-5fbd-8a41-931d1b292d53
STIX ID: report--6fabf53f-e3d2-5fbd-8a41-931d1b292d53
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved logins, cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox; it bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process (using Early Bird APC) to call the IElevator COM interface and retrieve decryption keys, and uses DPAPI/NSS approaches for other browsers. The report covers implementation details, evasion techniques, attack scenarios, detection opportunities, and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
