Ensuring Data Security During Hardware Disposal
ID: 88f9e564-13a3-5fb6-a73c-fb3723b8c551
STIX ID: report--88f9e564-13a3-5fb6-a73c-fb3723b8c551
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials, cookies, OAuth tokens, credit card data, autofill entries, and history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It bypasses Chromium App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI or NSS decryption where applicable, includes multiple EDR-evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, file-handle duplication), outputs structured JSON, and is aimed at red-team/assumed-breach use but could be abused by adversaries to enable cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
