Active Web Application Security Reconnaissance Tool
ID: 9574f71d-fd52-5f53-b40a-fc340140f9df
STIX ID: report--9574f71d-fd52-5f53-b40a-fc340140f9df
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential harvesting tool (available as precompiled binaries) that extracts browser‑stored secrets — saved passwords, cookies, OAuth refresh tokens, credit cards, autofill entries and history — from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox. It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and recover encryption keys, includes DPAPI and NSS handling for other browsers, and incorporates operational evasion features; the report covers usage, detection opportunities, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
