June 2008 Commenter of the Month Competition Winner!
ID: b3383d11-c0c8-54c2-bdf8-3f352635563d
STIX ID: report--b3383d11-c0c8-54c2-bdf8-3f352635563d
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, and uses DPAPI or NSS handling for other browsers; extracted artifacts (cookies, saved logins, OAuth tokens, credit cards, autofill, history) are written to JSON. The README emphasizes red-team use, describes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and provides detection and mitigation recommendations for EDR and policy-level controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
