Sophos Launches FREE Anti-Virus Software For Mac
ID: d31802d6-774b-5f9b-a4ca-db4ff5e6f58f
STIX ID: report--d31802d6-774b-5f9b-a4ca-db4ff5e6f58f
Feed Name: Darknet
This report analyzes DumpBrowserSecrets, a publicly available post‑exploitation tool designed to harvest stored credentials and session tokens from major Windows browsers (Chromium-based and Firefox). It details the tool's architecture (an executable and a DLL), techniques to bypass Chrome's App‑Bound Encryption by spawning a headless Chromium and using IElevator COM via Early Bird APC DLL injection, support for DPAPI and NSS decryption, extracted data types (cookies, saved logins, OAuth tokens, credit cards, autofill, history), operational evasion features, recommended detection points, and its use case in red team and assumed‑breach testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
