‘Untraceable’ Phone Frauders Vishing for Credit Cards
ID: 0e9e3743-4efd-5345-a691-2ac87ef4406f
STIX ID: report--0e9e3743-4efd-5345-a691-2ac87ef4406f
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using a headless Chromium process, Early Bird APC DLL injection, and the IElevator COM interface), Opera/Vivaldi (DPAPI), and Firefox (NSS). It outputs structured JSON of recovered cookies, OAuth refresh tokens, saved logins, credit cards and history, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is presented as a red‑team tool useful for testing credential exposure and endpoint defenses, with detection opportunities identified for process injection, headless browser instantiation, database reads, and IElevator calls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
