Sniff & Intercept Web Sessions With Android
ID: 6fc9e007-7dd2-585d-afb5-a4c8eaedc68c
STIX ID: report--6fc9e007-7dd2-585d-afb5-a4c8eaedc68c
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored credentials and session artifacts (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) from major Chromium- and Firefox-based browsers. It includes a DLL injection technique (Early Bird APC) to leverage the IElevator COM interface and bypass Chrome's App‑Bound Encryption, handles DPAPI and NSS decryption for other browsers, implements several evasion techniques for EDR, and outputs structured JSON for red team or attacker use—enabling rapid account takeover and lateral movement from a compromised Windows host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
