Taiwan Kings of Spam from CipherTrust
ID: 0357c3cc-b1d2-53a2-91ba-5ea2ac4b5926
STIX ID: report--0357c3cc-b1d2-53a2-91ba-5ea2ac4b5926
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored credentials and session tokens from Chromium- and Firefox-based browsers by bypassing protections (App-Bound Encryption via IElevator COM when injected into a headless Chromium process, DPAPI for some browsers, and NSS handling for Firefox). It outputs structured JSON, includes evasion techniques (Early Bird APC injection, PPID/argument spoofing, API hashing, custom SQLite parser), and is presented for red-team assumed‑breach use but carries significant abuse potential for attacker-driven credential theft, lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
