How To Send A File Securely Without Additional Software
ID: e5c236f3-4aaa-5403-9ae9-7cc9ebea7b5d
STIX ID: report--e5c236f3-4aaa-5403-9ae9-7cc9ebea7b5d
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox; it bypasses Chrome App-Bound Encryption (Chrome 127+) by injecting a DLL into a headless Chromium process to call the IElevator COM interface and retrieve decryption keys. The report covers the executable + DLL architecture, supported encryption models (App-Bound, DPAPI, NSS), evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), usage examples, detection opportunities, and mitigation recommendations for defenders and red teams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
