Merry Christmas 2012 From Darknet
ID: 97649d2c-19ff-5f88-9691-594a7154cf99
STIX ID: report--97649d2c-19ff-5f88-9691-594a7154cf99
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and tokens from Chromium- and Gecko-based browsers. It implements an App-Bound Encryption bypass for modern Chromium builds by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt the app_bound_encrypted_key, and then parses and decrypts browser SQLite/JSON stores; it also handles DPAPI and NSS models for other browsers, outputs structured JSON, and includes multiple evasion techniques aimed at EDR and forensic detection — making it a high-impact capability for lateral movement and SaaS account takeover in assumed-breach engagements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
