Viruses & Malware Monitored on a Dynamic World Map
ID: 8b7fe487-1d47-5761-989e-3498d9427ed1
STIX ID: report--8b7fe487-1d47-5761-989e-3498d9427ed1
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that harvests browser-stored credentials and session data from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It injects a DLL into a headless Chromium process to use the IElevator COM interface to decrypt app‑bound keys, parses on-disk SQLite/JSON stores, and outputs structured JSON containing cookies, OAuth refresh tokens, saved logins, credit cards, autofill data, and history; the tool includes multiple evasion techniques and is intended for red team use but presents a high-risk credential-exposure capability for compromised developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
