Month of Browser Bugs (MoBB)
ID: 7d1a3196-d008-5ac6-ae97-4e632b67318f
STIX ID: report--7d1a3196-d008-5ac6-ae97-4e632b67318f
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that extracts browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks) from major Chromium- and Gecko-based browsers. It uses a headless Chromium process with Early Bird APC DLL injection to leverage the IElevator COM interface and decrypt App-Bound Encryption keys (Chrome/Brave/Edge), retrieves DPAPI keys for Opera/Vivaldi variants, and handles Firefox NSS decryption directly; the tool includes evasion features and is intended for red team/assumed-breach testing but also represents a capability attackers could abuse for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
