VBootkit Bypasses Vista’s Digital Code Signing
ID: 8fc9bda3-ace6-53f8-926f-27fd24142f16
STIX ID: report--8fc9bda3-ace6-53f8-926f-27fd24142f16
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool aimed at extracting saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium- and Gecko-based browsers on Windows. The report describes how the tool bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS encryption for other browsers, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and provides detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
