E-mail Scammers Target Microsoft Users
ID: 0e321fae-f6b4-5454-be55-fcf8bb3728b2
STIX ID: report--0e321fae-f6b4-5454-be55-fcf8bb3728b2
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history) from Chrome/Edge/Brave (App‑Bound Encryption bypass via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It uses DLL injection into a headless Chromium process to decrypt app_bound_encrypted_key, parses on-disk SQLite/JSON stores, outputs structured JSON, includes evasion techniques for EDR, and provides detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
