Security Companies Fight Against Microsoft Security Center
ID: 8ebb45b4-96c8-5366-b69a-0735f0de90b5
STIX ID: report--8ebb45b4-96c8-5366-b69a-0735f0de90b5
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract saved credentials, session cookies, OAuth tokens, credit card data, autofill entries, history, and bookmarks. The report describes its architecture (an executable plus a DLL injected into a headless Chromium process using Early Bird APC to decrypt app_bound_encrypted_key), evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, detection opportunities, and its relevance for red-team testing and assessing credential exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
