High Speed Network Authentication Cracking Tool
ID: c3bf97e9-cb65-50af-b02d-6381ba969245
STIX ID: report--c3bf97e9-cb65-50af-b02d-6381ba969245
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool targeting major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). It uses a headless Chromium + injected DLL to obtain app_bound_encrypted_key through the IElevator COM interface (Early Bird APC injection), parses browser SQLite/JSON stores, extracts cookies, saved logins, OAuth refresh tokens, credit cards and autofill data, and outputs structured JSON for red-team or offensive use; the report also documents evasion techniques, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
