HOPE Speak Steven Rombom (Rambam) Charged
ID: bbf6a668-1d29-5aad-be8c-342847cb1202
STIX ID: report--bbf6a668-1d29-5aad-be8c-342847cb1202
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium and Firefox-based browsers by bypassing App-Bound Encryption (Chrome/Edge/Brave), DPAPI (Opera/Vivaldi), and NSS (Firefox). The report details its DLL injection via Early Bird APC and IElevator COM interface to decrypt keys inside a headless browser, its operational evasion techniques, extracted data types (cookies, OAuth refresh tokens, saved logins, credit cards, autofill, history), and detection/mitigation approaches, noting the tool's capability to enable rapid cloud account takeover from a compromised developer workstation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
