Odysseus Proxy for MITM Attacks Testing Security of Web Applications.
ID: 870b332c-9c48-523a-af03-2952cc39f669
STIX ID: report--870b332c-9c48-523a-af03-2952cc39f669
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium-based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox; the tool includes operational evasion techniques, outputs structured JSON, and is intended for red-team assumed‑breach testing but could be repurposed by real attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
