Adobe PDF Reader Rewrite To Include Sandbox Feature
ID: c397bcff-8b2e-5ecc-9d8a-23a65995ca6d
STIX ID: report--c397bcff-8b2e-5ecc-9d8a-23a65995ca6d
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts cookies, saved passwords, OAuth refresh tokens, credit card details, autofill data, and history from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It implements a DLL injection + Early Bird APC technique to spawn a headless Chromium process and use the IElevator COM interface to decrypt App‑Bound Encryption keys (Chrome 127+), handles DPAPI and NSS decryption for other browsers, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is presented for red-team assumed-breach testing while also being relevant to defensive detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
