Facebook Attachment Uploader Owned By A Space
ID: 9fbfd027-5ce7-5925-b01c-a5d46215d2e1
STIX ID: report--9fbfd027-5ce7-5925-b01c-a5d46215d2e1
Feed Name: Darknet
This report analyzes DumpBrowserSecrets, a Windows post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) from Chromium-based and Firefox browsers by bypassing App-Bound Encryption and DPAPI/NSS protections; it explains the executable+DLL architecture, Early Bird APC DLL injection into a headless Chromium process to use the IElevator COM interface, evasion techniques, use-cases for red teams, and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
