McAfee buying Tel Aviv startup Onigma for $15-25 million cash
ID: 8b0a2ad0-58ce-5dcb-9c60-55c10267ecf4
STIX ID: report--8b0a2ad0-58ce-5dcb-9c60-55c10267ecf4
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool designed to harvest browser-stored credentials and session data from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt keys, retrieves DPAPI keys where applicable, parses on-disk SQLite/JSON stores, and outputs structured JSON. The report covers extracted data types, operational evasion features, usage examples, detection signals (process injection, IElevator calls, unusual headless browser activity, SQLite reads), and mitigation recommendations such as using dedicated credential managers and EDR rules targeting the described behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
