Uber Paid Hackers To Hide 57 Million User Data Breach
ID: 94d35cc7-82d0-5dca-9d10-d2d0440e840e
STIX ID: report--94d35cc7-82d0-5dca-9d10-d2d0440e840e
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session data across major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox by using techniques including Early Bird APC DLL injection into a headless Chromium process to invoke the IElevator COM interface and decrypt App-Bound Encryption keys, DPAPI extraction for some browsers, and NSS decryption for Firefox; it outputs structured JSON and incorporates evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing) to reduce detection, making it a potent capability for red teams and a credible risk if abused by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
