US Investigators Pinpoint Author Of Google Attack Code
ID: c5f264cc-5116-5852-93c5-28f56bc23646
STIX ID: report--c5f264cc-5116-5852-93c5-28f56bc23646
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by injecting a DLL into a headless browser process to call the IElevator COM interface, supports DPAPI and NSS decryption methods for other browsers, includes operational evasion tricks (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), and outputs structured JSON useful for red team or malicious reuse; the report also describes detection points and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
