Your Employees Don’t Care About Your Data
ID: 884dd6fd-e34f-5c64-b43f-9a4cac7911d9
STIX ID: report--884dd6fd-e34f-5c64-b43f-9a4cac7911d9
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that extracts cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report covers usage, an attack scenario demonstrating fast credential extraction for lateral/cloud account takeover, detection opportunities (process injection, headless browser instantiation, reads of browser SQLite DBs, IElevator calls) and mitigations (use of standalone credential managers and EDR rules monitoring IElevator and headless browser behavior).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
