ISIS Running 24-Hour Terrorist Crypto Help-desk
ID: b1f7508a-7854-560a-b808-8678bbb094a0
STIX ID: report--b1f7508a-7854-560a-b808-8678bbb094a0
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that extracts credentials, session cookies, OAuth refresh tokens, credit card data and browsing history from Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave via headless Chromium + Early Bird APC DLL injection using the IElevator COM interface, handles DPAPI and NSS-encrypted stores for other browsers, and includes operational evasion features; the tool outputs structured JSON suitable for red team use but also usable by malicious actors to achieve cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
