Jan 2006 Virus and Spam Statistics
ID: bf27ccc5-36ca-5513-8465-df490c2f333b
STIX ID: report--bf27ccc5-36ca-5513-8465-df490c2f333b
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chrome, Edge, Brave (App‑Bound Encryption), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) to extract saved passwords, session cookies, OAuth tokens, credit cards, autofill data and browsing history. It achieves this by spawning a headless Chromium process and injecting a DLL via Early Bird APC to leverage the IElevator COM interface and decrypt app_bound_encrypted_key for Chromium-based browsers, or by retrieving DPAPI/NSS secrets for other browsers; output is written as structured JSON. The repo documents operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), provides usage examples for red team/assumed-breach exercises, and outlines detection and mitigation opportunities such as monitoring IElevator calls, unexpected process injection, headless browser creation, and unauthorized reads of browser SQLite files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
