CLR and SQL Server 2005
ID: b3649ba0-1092-5016-8c82-d436a0a5e91e
STIX ID: report--b3649ba0-1092-5016-8c82-d436a0a5e91e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It uses a compiled executable plus a DLL injected into a headless Chromium process to bypass App-Bound Encryption via the IElevator COM interface and retrieves DPAPI or NSS-protected secrets, producing structured JSON output. The tool includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, handle duplication, and a custom SQLite parser), is intended for red team assumed-breach testing, and poses a high risk for lateral movement and cloud account takeover if used on compromised developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
