Defense Workers Warned About Spy Coins for Espionage
ID: 0b7553b2-435f-552d-91a5-c46772818e86
STIX ID: report--0b7553b2-435f-552d-91a5-c46772818e86
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chromium-based and Firefox browsers on Windows. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (via Early Bird APC) to call the IElevator COM interface to decrypt the app_bound_encrypted_key, retrieves DPAPI keys for some Chromium forks, or uses NSS decryption for Firefox; outputs structured JSON and includes several operational evasion features intended for red-team use and defensive testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
