Tyton – Kernel-Mode Rootkit Hunter for Linux
ID: d54a10cc-832c-5cc0-9af3-aafd84a31702
STIX ID: report--d54a10cc-832c-5cc0-9af3-aafd84a31702
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials and tokens from Chromium-based and Firefox browsers by combining a compiled executable with a DLL injected into a headless Chromium process to bypass App‑Bound Encryption (IElevator COM) and using DPAPI/NSS techniques for other browsers; it outputs structured JSON and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report covers supported browsers, extracted data types, attack scenarios (fast extraction of active SaaS session cookies and OAuth tokens), detection opportunities, and mitigation recommendations such as using out-of-browser credential managers and EDR monitoring for IElevator calls and unexpected headless browser instantiation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
