Google Desktop Privacy? OR Lack Of..
ID: e46f23e4-754f-5d86-9bf4-15b22d1d03c0
STIX ID: report--e46f23e4-754f-5d86-9bf4-15b22d1d03c0
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chrome/Edge/Brave (using an App‑Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses a headless Chromium spawn and Early Bird APC DLL injection to invoke the IElevator COM interface to decrypt app_bound_encrypted_key, includes multiple runtime evasion techniques, outputs structured JSON for red team use, and outlines detection and mitigation strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
