logo

DeepSound – Audio Steganography Tool

ID: ebd65372-6ffc-5d30-88b2-0b6aab39bb7a

STIX ID: report--ebd65372-6ffc-5d30-88b2-0b6aab39bb7a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2019-03-05

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Windows browsers (Chrome/Brave/Edge via an App‑Bound Encryption bypass, Opera/Opera GX/Vivaldi via DPAPI, and Firefox via NSS). The tool spawns a headless Chromium, injects a DLL using Early Bird APC to leverage the IElevator COM interface and decrypt the app_bound_encrypted_key, parses browser SQLite/JSON stores, and writes structured JSON output; it also includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report details attack scenarios, detection opportunities (process injection, IElevator calls, non-browser accesses to Login Data/Cookies/Web Data), and mitigations such as moving secrets out of browsers and EDR monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.