HiddenWall – Create Hidden Kernel Modules
ID: 73776019-3028-5991-bbef-122b8f3455a7
STIX ID: report--73776019-3028-5991-bbef-122b8f3455a7
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, returns decrypted keys to the executable, parses SQLite/JSON stores, and outputs structured JSON; the report covers capabilities, evasion, an attack scenario demonstrating cloud account takeover risk, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
