Web Application Scanner / Black-box testing
ID: d7266dca-7307-534b-93d1-68d3541858a9
STIX ID: report--d7266dca-7307-534b-93d1-68d3541858a9
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation tool that harvests credentials and session data from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and decrypting stored keys; it handles DPAPI and NSS for other browsers. The tool extracts high-value artifacts (OAuth refresh tokens, active session cookies, plaintext credentials, credit cards) quickly, includes runtime evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is distributed as precompiled binaries intended for red-team use but usable by attackers, with guidance on detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
