Russia Heavy Handed Registration for Wifi
ID: ca239d1f-bf34-5acf-b572-8e1e5e52dc06
STIX ID: report--ca239d1f-bf34-5acf-b572-8e1e5e52dc06
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials and tokens across major Windows browsers by bypassing App-Bound Encryption (via DLL injection into a headless Chromium process and use of the IElevator COM interface) and handling DPAPI/NSS for other browsers. It extracts cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history, outputs structured JSON, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is intended for red team/assumed-breach testing but poses a significant risk if abused by threat actors; detection and mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
