Version Detection, CMS Identification, Enumeration & Server Scanning Tool
ID: aeeac7e2-3007-5e42-a72a-a0746cadce9e
STIX ID: report--aeeac7e2-3007-5e42-a72a-a0746cadce9e
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome, Edge, Brave, Opera (and variants), Vivaldi, and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, includes DPAPI and NSS handling for other browsers, and implements operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing); the report includes attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
