High-Performance (Open Source) Web Application Security Scanner Framework
ID: 77991fd8-e49e-5f07-bf3f-c915b4480084
STIX ID: report--77991fd8-e49e-5f07-bf3f-c915b4480084
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation Windows tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, etc.) across Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, includes DPAPI and NSS handling for other browsers, and incorporates evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report describes attack scenarios, output formats, detection opportunities (injection, IElevator calls, reads of browser SQLite DBs), and mitigation guidance including using dedicated credential managers and EDR policies that monitor IElevator and headless browser behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
