Israeli Hackers Join the War Against Palestinian Sites
ID: ae865839-e592-53dd-9a3d-db10af718a82
STIX ID: report--ae865839-e592-53dd-9a3d-db10af718a82
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that extracts browser-stored secrets (passwords, session cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from major Windows browsers. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface, and decrypting stored keys; it also handles DPAPI and Firefox NSS storage, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parser), writes structured JSON output, and is positioned as a red-team tool for assumed-breach assessments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
