Criminal Rings Hijacking Unused IPv4 Address Spaces
ID: 1f2e7bc4-cafb-5dc3-8a1c-6a3ae9f17516
STIX ID: report--1f2e7bc4-cafb-5dc3-8a1c-6a3ae9f17516
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a spawned headless Chromium process to use the IElevator COM interface, implements DPAPI and NSS handling for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and outputs structured JSON for red-team or adversary use; the report also outlines detection and mitigation strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
