REMnux: A Linux Distribution For Reverse-Engineering Malware
ID: b083526e-0c56-55c4-9f89-66861d1501a3
STIX ID: report--b083526e-0c56-55c4-9f89-66861d1501a3
Feed Name: Darknet
### Executive Summary DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It specifically implements a bypass for Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and can complete extraction in under 30 seconds on a compromised Windows host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
