Metasploit Site Hijacked by ARP Poisoning Attack
ID: a413f9a9-6f1d-5768-b33d-91e12e74c83f
STIX ID: report--a413f9a9-6f1d-5768-b33d-91e12e74c83f
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials, session cookies, OAuth refresh tokens, credit card data and browsing history from major browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass using IElevator; Opera/Opera GX/Vivaldi via DPAPI; Firefox via NSS). The report details the tool's architecture (DumpBrowserSecrets.exe + DllExtractChromiumSecrets.dll), DLL injection via Early Bird APC into a headless Chromium process, named-pipe communication, custom SQLite parsing, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, red-team relevance, detection opportunities and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
