Navy Sys Admin Hacks Into Databases From Aircraft Carrier
ID: c96f640d-9640-5a17-8156-b1a7cfefeac1
STIX ID: report--c96f640d-9640-5a17-8156-b1a7cfefeac1
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium spawning and DLL injection (Early Bird APC) to access the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and outputs structured JSON to aid red team or adversary credential theft and SaaS account takeover; the report also outlines detection and mitigation strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
