Scan For Files Vulnerable To LFI (Local File Inclusion)
ID: c02871f9-ae86-54db-b1b3-6edfca80a061
STIX ID: report--c02871f9-ae86-54db-b1b3-6edfca80a061
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It spawns headless Chromium and injects a DLL (Early Bird APC) to use the IElevator COM interface for decrypting app_bound_encrypted_key, parses on‑disk SQLite/JSON stores, writes structured JSON output, and includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication and a custom SQLite parser). The report details attack scenarios, red‑team relevance, detection opportunities (monitoring IElevator calls, unexpected process injection, headless browser instantiation, non‑browser reads of Login Data/Cookies/Web Data) and mitigation advice such as using external credential managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
