Microsoft Enhanced Mitigation Evaluation Toolkit (EMET)
ID: c98587ab-c21b-577b-9ee0-1cd2004b1106
STIX ID: report--c98587ab-c21b-577b-9ee0-1cd2004b1106
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation credential-harvesting tool that extracts browser-stored secrets from Chrome/Edge/Brave (via an App-Bound Encryption IElevator COM bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The report details its executable+DLL architecture, Early Bird APC DLL injection into headless Chromium to decrypt app_bound_encrypted_key, supported data types (passwords, cookies, OAuth tokens, credit cards, autofill, history), operational evasion features, an example attack scenario, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
