Donations Flood in for Guilty Security Researcher Guillaume Tena
ID: a961b80d-4c94-5bd6-a691-cb294497ee59
STIX ID: report--a961b80d-4c94-5bd6-a691-cb294497ee59
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium‑based browsers by injecting a DLL into a headless browser process to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes multiple EDR‑evasion techniques, outputs structured JSON, and is positioned primarily for red team/assumed‑breach testing but presents a realistic threat if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
