Windows Registry Infecting Malware Has NO Files
ID: e2767089-9f72-55ed-9fea-788b7f6b9f81
STIX ID: report--e2767089-9f72-55ed-9fea-788b7f6b9f81
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session material across Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to call the IElevator COM interface, retrieves DPAPI/NSS keys for other browsers, parses on-disk SQLite/JSON stores, and outputs structured JSON containing passwords, cookies, OAuth refresh tokens, autofill data, and history. The report covers operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, an assumed-breach attack scenario, and detection/mitigation strategies for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
