A Forensic Analysis of the Lost Veteran’s Administration Laptop
ID: b843b635-306d-5299-af45-a7d76fe7cd60
STIX ID: report--b843b635-306d-5299-af45-a7d76fe7cd60
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (openly distributed as a Windows executable and DLL) that extracts saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data and browsing history from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using a headless Chromium process and IElevator COM interface), Opera/Vivaldi variants (DPAPI), and Firefox (NSS). The report describes the tool's architecture, DLL injection and Early Bird APC technique, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), usage examples, detection opportunities, and red‑team relevance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
