Pentagon E-mail System HACKED
ID: b7e699e5-7b05-5923-a94b-61f0291786a3
STIX ID: report--b7e699e5-7b05-5923-a94b-61f0291786a3
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks) from Chromium-based and Gecko-based browsers. It implements an App-Bound Encryption bypass for Chrome/Brave/Edge by spawning a headless Chromium process and injecting a DLL using Early Bird APC to call the IElevator COM interface, retrieves DPAPI or NSS-protected keys for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team/assumed-breach testing while highlighting detection and mitigation points.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
