Information Security Adversarial Simulation Tool
ID: 810f0bd1-933d-5e04-8846-1fd3f386888b
STIX ID: report--810f0bd1-933d-5e04-8846-1fd3f386888b
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based browsers (Chrome, Edge, Brave) and Firefox to extract saved passwords, cookies, OAuth tokens, credit card data, autofill entries, and history. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, retrieves DPAPI and NSS secrets where applicable, includes multiple evasion techniques to reduce EDR detection, and is presented as a red-team utility for assessing the risk of browser-stored credentials and SaaS account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
