UK Encryption Backdoor Law Passed Via Investigatory Powers Act
ID: f650d682-dec7-58b8-9022-d436b39e0a38
STIX ID: report--f650d682-dec7-58b8-9022-d436b39e0a38
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) across Chrome, Edge, Brave, Opera-family, Vivaldi, and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (via Early Bird APC injection) to retrieve decryption keys, uses DPAPI or NSS decryption for other browsers, includes multiple operational evasion techniques, outputs structured JSON, and is positioned as a red-team utility for testing credential exposure and endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
