UFO ‘Hacker’ Gary McKinnon Reveals What He Found
ID: a2cb1961-fe55-5c14-b554-22d5717b8a82
STIX ID: report--a2cb1961-fe55-5c14-b554-22d5717b8a82
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest browser-stored credentials and tokens from Windows hosts across Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI/NSS handling for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and outputs structured JSON containing cookies, OAuth refresh tokens, saved logins, autofill data, and history — enabling rapid lateral movement or cloud account takeover if run on a compromised developer workstation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
