76% Of Users Exposing Their Browsing Histories
ID: b9c56056-7d80-50e3-89ec-0e9ca199bcdd
STIX ID: report--b9c56056-7d80-50e3-89ec-0e9ca199bcdd
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers by bypassing App-Bound Encryption, DPAPI, and NSS protections; it injects a DLL into a headless Chromium via Early Bird APC to use the IElevator COM interface to decrypt app-bound keys, parses on-disk SQLite/JSON stores, and outputs structured JSON while employing multiple evasion techniques — the report documents functionality, supported browsers, usage, attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
