Moving Ahead in the War Against Botnets
ID: 0292a56a-4482-5360-9283-79226ad24ad6
STIX ID: report--0292a56a-4482-5360-9283-79226ad24ad6
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox by using techniques including headless Chromium spawning, Early Bird APC DLL injection, an IElevator COM App‑Bound Encryption bypass, DPAPI/NSS decryption and operational evasion (string obfuscation, API hashing, PPID/argument spoofing); the report covers usage, extracted data, an example attack scenario, detection opportunities and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
