Passive Web Application Vulnerability Scanner
ID: ccd2a358-bcfb-5086-b963-c4c264d9e19b
STIX ID: report--ccd2a358-bcfb-5086-b963-c4c264d9e19b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that targets Chromium‑based and Firefox browsers to extract saved passwords, session cookies, OAuth tokens, credit card data, and browsing history; it bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, and includes multiple operational evasion techniques—making it a high‑risk capability for lateral movement and cloud account takeover if misused, while also being positioned for red‑team use and endpoint control testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
