Comprehensive Set Of Known Attack Sequences
ID: 925b6661-528f-5b57-a362-d1bf92832a58
STIX ID: report--925b6661-528f-5b57-a362-d1bf92832a58
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill, and history; it uses headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to decrypt app_bound_encrypted_key and includes operational evasion features and structured JSON output for red‑team use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
