AutoPwnKey – AV Evasion via Simulated User Interaction
ID: 79d3632f-1754-56ad-a1ec-107b29ca533b
STIX ID: report--79d3632f-1754-56ad-a1ec-107b29ca533b
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth tokens, credit cards, autofill data, history and bookmarks) across Chromium- and Gecko-based browsers by bypassing App-Bound Encryption via DLL injection into a headless Chromium process and handling DPAPI/NSS decryption; the report covers implementation details, evasion techniques, an attack scenario, detection indicators, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
