Avira Joins The Crowd & Starts To Offer Mac Antivirus Software
ID: 17436c4d-b4c7-5b42-859f-da42659271fe
STIX ID: report--17436c4d-b4c7-5b42-859f-da42659271fe
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (available as precompiled binaries) that targets major Windows browsers — Chrome, Edge, Brave (App‑Bound Encryption via IElevator COM bypass), Opera/Vivaldi (DPAPI), and Firefox (NSS) — to extract saved credentials, session cookies, OAuth tokens, credit card data and browsing history. The tool uses DLL injection (Early Bird APC) into a headless Chromium process to decrypt app_bound_encrypted_key, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is positioned for red team/assumed‑breach testing while also presenting a clear malicious capability if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
