Google has no license for China service
ID: eab523aa-1359-537d-ae38-35c645360c24
STIX ID: report--eab523aa-1359-537d-ae38-35c645360c24
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by using DLL injection into a headless Chromium process to bypass App‑Bound Encryption via the IElevator COM interface, and by handling DPAPI/NSS for other browsers; it outputs structured JSON and includes evasion features to reduce EDR detection. The report covers supported data types (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history), usage examples, attack scenarios demonstrating rapid credential extraction for lateral movement and cloud account takeover, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
