logo

New Password Stealing Trojan Targets WoW Players

ID: 1f395cc8-d0ca-55da-9445-c85ec67f0047

STIX ID: report--1f395cc8-d0ca-55da-9445-c85ec67f0047

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-05-06

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a post-exploitation Windows tool that harvests browser-stored credentials (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, includes DPAPI and NSS handling for other browsers, and incorporates evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report covers usage, output, attack scenarios, detection points (process injection, IElevator calls, database reads), and mitigation recommendations such as moving secrets to dedicated credential managers and improving EDR detection of headless/browser-injected contexts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.