Privileged Account Threat Detection Tool
ID: e830cd76-1d1a-55a9-b232-a2ddae4df9cd
STIX ID: report--e830cd76-1d1a-55a9-b232-a2ddae4df9cd
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool designed to harvest browser-stored secrets (cookies, saved logins, OAuth tokens, credit cards, autofill data, history, and bookmarks) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox; it bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and returns decrypted keys to an executable that parses and decrypts on-disk SQLite/JSON stores. The report details implementation, supported browsers and encryption models (App-Bound V20, DPAPI V10, NSS), operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), an example attack scenario, detection opportunities, and mitigation recommendations for enterprise defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
