Reaper – Unified Application Security Testing with AI Support
ID: 6ffcece8-69ed-53f0-9072-84689882ad6a
STIX ID: report--6ffcece8-69ed-53f0-9072-84689882ad6a
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) across Chromium-based browsers and Firefox. The report details its operation — spawning a headless Chromium process, injecting a DLL via Early Bird APC to leverage the IElevator COM interface and decrypt App-Bound Encryption keys, handling DPAPI and NSS models for other browsers, and implementing evasion techniques — and discusses attack scenarios, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
