User Mode Program Can Disable User Access Control
ID: c1fcd6fd-d6dd-512c-8cf5-335b750c2c08
STIX ID: report--c1fcd6fd-d6dd-512c-8cf5-335b750c2c08
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation browser credential harvesting tool that targets Chrome/Edge/Brave (via an IElevator App‑Bound Encryption bypass using Early Bird APC DLL injection), Opera/Vivaldi (DPAPI), and Firefox (NSS) to extract saved passwords, cookies, OAuth refresh tokens, credit card data, autofill, and history into JSON. The report documents implementation details, evasion techniques, supported browsers, example attacker workflows, detection opportunities, and red‑team relevance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
