Express Scripts Offers $1million Reward for Cyber Extortionists
ID: 1dab157c-eaf1-58c8-b200-653795d727d2
STIX ID: report--1dab157c-eaf1-58c8-b200-653795d727d2
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, handles DPAPI and NSS encryption models for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool outputs structured JSON of recovered artifacts (cookies, saved logins, OAuth tokens, credit cards, autofill, history) and is positioned for red-team use but presents clear abuse potential for lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
