Defend Against OS Fingerprinting for OpenBSD
ID: cd43f26e-8068-589f-8a24-33750b4057cb
STIX ID: report--cd43f26e-8068-589f-8a24-33750b4057cb
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation browser credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, browsing history, and bookmarks from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless process and injecting a DLL to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, and includes operational evasion techniques (string obfuscation, API hashing, Early Bird APC injection, PPID/argument spoofing, handle duplication, and a custom SQLite parser), making it a high‑impact capability for lateral movement and cloud account takeover in compromised environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
