IE Address Bar Spoofing
ID: def43fd9-71af-52ca-af8c-48bc24cbb111
STIX ID: report--def43fd9-71af-52ca-af8c-48bc24cbb111
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens across major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI or NSS-protected keys as appropriate, and decrypts SQLite/JSON-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks). The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parsing), outputs structured JSON, and is intended for red-team/assumed-breach testing but represents a high-risk capability if abused by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
