logo

Two Thirds Of All Phishing Attacks Carried Out By Single Group

ID: 1179041c-dce3-5c36-89c3-a66f06f39ece

STIX ID: report--1179041c-dce3-5c36-89c3-a66f06f39ece

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-05-14

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests credentials and session data from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It uses headless Chromium spawning and Early Bird APC DLL injection to leverage the IElevator COM interface and bypass Chrome's App‑Bound Encryption, retrieves DPAPI/NSS secrets where applicable, and outputs structured JSON; the report covers operational usage, evasion features, detection opportunities, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.