Merry Christmas 2009
ID: f8507492-355e-5fd1-80ba-1020523d0fac
STIX ID: report--f8507492-355e-5fd1-80ba-1020523d0fac
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool from Maldev Academy that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from Chromium-based and Firefox browsers on Windows. It bypasses Chrome’s App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, returns decrypted keys via a named pipe, and decrypts on-disk SQLite/JSON stores; for DPAPI-based browsers it retrieves DPAPI keys and Firefox uses NSS decryption. The tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs JSON, completes extraction quickly, and is intended for red team/assumed-breach testing but represents a high-risk capability for credential and session token theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
