CredMaster – Anonymous AWS‑Backed Password Spraying Toolkit
ID: 78707820-a401-5ad5-8601-2cf1c45731a7
STIX ID: report--78707820-a401-5ad5-8601-2cf1c45731a7
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chromium‑based and Gecko‑based browsers on Windows, using a headless Chromium + injected DLL to bypass Chrome's App‑Bound Encryption via the IElevator COM interface (and DPAPI/NSS handling for other browsers) to extract cookies, saved passwords, OAuth refresh tokens, credit cards, autofill data, and history; the report describes its components, operational evasion techniques, extraction output, usage examples, detection opportunities, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
