logo

Malware Writers Using Exclusion Lists To Linger

ID: 0fbbb163-08af-57aa-b80c-6f3830ec5780

STIX ID: report--0fbbb163-08af-57aa-b80c-6f3830ec5780

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-12-08

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool (released by Maldev Academy) that harvests browser-stored secrets — saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history — from Chromium-based and Mozilla browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and incorporates evasion features to reduce EDR detection; output is structured JSON for operator use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.