Don’t Sweat or Scratch Your Face Whilst Flying
ID: bf2d1b2a-4579-59b6-a92a-5f4d9100072b
STIX ID: report--bf2d1b2a-4579-59b6-a92a-5f4d9100072b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, retrieves DPAPI keys for Opera-family browsers, and uses NSS decryption for Firefox; it includes multiple evasion features and outputs structured JSON for red-team use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
