More Drama About Hillary Clinton's E-mail Leak
ID: 81bac2d1-db91-5a80-af16-74b574082283
STIX ID: report--81bac2d1-db91-5a80-af16-74b574082283
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data and browsing history from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses DLL injection into a headless Chromium process (Early Bird APC) to leverage the IElevator COM interface and decrypt app_bound_encrypted_key, includes multiple operational evasion techniques, outputs structured JSON for red-team use, and highlights detection and mitigation opportunities such as monitoring IElevator calls, headless browser instantiation, and unexpected reads of browser SQLite files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
