logo

Criminal Rings Hijacking Unused IPv4 Address Spaces

ID: 1f2e7bc4-cafb-5dc3-8a1c-6a3ae9f17516

STIX ID: report--1f2e7bc4-cafb-5dc3-8a1c-6a3ae9f17516

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-06-23

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a spawned headless Chromium process to use the IElevator COM interface, implements DPAPI and NSS handling for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), and outputs structured JSON for red-team or adversary use; the report also outlines detection and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.