Hackers Get Hold Of Wildcard Google SSL Certificate
ID: 7cfc7f10-3b94-5c0b-9cd2-8a4795260870
STIX ID: report--7cfc7f10-3b94-5c0b-9cd2-8a4795260870
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser‑stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill entries, history, and bookmarks) from Chromium‑based browsers and Firefox. It bypasses Chrome’s App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI keys for some Chromium forks, and handles Firefox via NSS decryption; the README documents usage, evasion (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), detection opportunities, and red-team relevance, showing how recovered tokens can enable cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
