European Commission Pushing For Encryption Backdoors
ID: b46c3604-4e26-5c4c-8ef9-3aab35e945b3
STIX ID: report--b46c3604-4e26-5c4c-8ef9-3aab35e945b3
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI and NSS methods for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, and custom SQLite parsing). The tool outputs structured JSON of extracted data (passwords, cookies, OAuth tokens, credit cards, autofill, history) enabling rapid lateral movement and cloud session takeover; the report also describes detection points and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
