Logic Bomb Backfires on Hacker Employee
ID: b19f8815-51f4-5644-bc95-1bc3f192103f
STIX ID: report--b19f8815-51f4-5644-bc95-1bc3f192103f
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It implements an App‑Bound Encryption bypass for Chrome 127+ by injecting a DLL into a headless Chromium process to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The report covers usage, extracted data types, an attack scenario demonstrating rapid cloud account takeover potential, and detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
