Techm4sters Releases ProTech Security Distribution
ID: fb77648e-730a-597c-9d8a-893adbdf5249
STIX ID: report--fb77648e-730a-597c-9d8a-893adbdf5249
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool (Windows executable + DLL) that targets Chromium- and Gecko-based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox; the tool includes multiple evasion techniques, outputs structured JSON, and is positioned for red team/assumed-breach testing while also representing a realistic threat to enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
