Exploitation Framework for Email Content Filters
ID: 8fecdd9b-f55f-5c8a-8cd2-11e6fdf74ec9
STIX ID: report--8fecdd9b-f55f-5c8a-8cd2-11e6fdf74ec9
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and history from Chromium-based and Firefox browsers by using DLL injection (Early Bird APC) and an IElevator COM bypass to defeat Chrome’s App-Bound Encryption; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red-team or operator use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
