Most Damaging Computer Attacks Rely on Stolen Logins
ID: 8a183027-0ceb-517a-a8d9-553e71699ac2
STIX ID: report--8a183027-0ceb-517a-a8d9-553e71699ac2
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major Windows browsers by bypassing App‑Bound Encryption (via DLL injection into a headless Chromium process and use of the IElevator COM interface) and handling DPAPI/NSS models for other browsers. The report details the tool's architecture, operational evasion techniques, example attack scenarios, detection opportunities (process injection, IElevator calls, reads of Login Data/Cookies/Web Data), and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
