Understanding the Deep Web, Dark Web, and Darknet (2025 Guide)
ID: eeb5e5be-d246-5a73-96f0-bd6dea805c58
STIX ID: report--eeb5e5be-d246-5a73-96f0-bd6dea805c58
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome/Brave/Edge via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS) to extract cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks. It spawns a headless Chromium process and injects a DLL using Early Bird APC to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red-team/assumed‑breach tool for assessing SaaS and browser credential exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
