Cyber Security Incident Management Platform
ID: 91f49899-b66d-57d3-bf76-a3ed9dbd780e
STIX ID: report--91f49899-b66d-57d3-bf76-a3ed9dbd780e
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts credentials and session data from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS secrets where applicable, and outputs structured JSON of cookies, saved logins, OAuth tokens, credit card data, autofill, and history; the report assesses operational use, detection vectors, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
