SHA-256 and SHA3-256 Are Safe For the Foreseeable Future
ID: 900ef565-a1cf-5e9a-ba84-8165a35b42cf
STIX ID: report--900ef565-a1cf-5e9a-ba84-8165a35b42cf
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that targets Chromium‑based and Gecko‑based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks. For Chrome/Edge/Brave it bypasses App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt the app_bound_encrypted_key; for Opera/Vivaldi it retrieves DPAPI keys and for Firefox it uses NSS decryption. The tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, is designed for red‑team/assumed‑breach use, and the report outlines detection and mitigation opportunities such as monitoring IElevator calls, headless browser spawning, and unexpected reads of browser SQLite files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
