Exploit MD5 Collisions For Malware Detection
ID: f1850b84-ab04-5533-a1c9-e0bd5d2e4536
STIX ID: report--f1850b84-ab04-5533-a1c9-e0bd5d2e4536
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation Windows tool that harvests saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chromium-based and Gecko-based browsers; it includes a DLL injection technique that leverages Early Bird APC and the IElevator COM interface to bypass Chrome's App-Bound Encryption, supports DPAPI and NSS decryption for other browsers, and incorporates evasion features to reduce detection—making it a powerful capability for credential theft and cloud account takeover in assumed-breach scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
