Technitium MAC Address Changer v4.8 Released for Download
ID: fa05ec7a-aa8a-5af2-a5aa-6edd4a4a539c
STIX ID: report--fa05ec7a-aa8a-5af2-a5aa-6edd4a4a539c
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, retrieves DPAPI or NSS-protected keys for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and is intended for red team/assumed-breach testing while also demonstrating a high-risk real-world credential theft vector that defenders should detect and mitigate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
