Microsoft Offers $250K Bounty for Conficker Author
ID: 26236793-b7ab-509a-9fa7-7fc9f49f1a5b
STIX ID: report--26236793-b7ab-509a-9fa7-7fc9f49f1a5b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from Chromium-based and Firefox browsers by bypassing App-Bound Encryption (via IElevator COM calls from an injected DLL in a headless Chromium process), DPAPI, and NSS protections; it outputs structured JSON and includes evasion features like string obfuscation, API hashing, PPID/argument spoofing, and file-handle duplication. The report covers supported browsers and data types (saved logins, cookies, OAuth tokens, credit cards, autofill, history), usage examples, operational attack scenarios (enabling cloud account takeover and lateral movement), detection opportunities (monitor IElevator calls, headless browser instantiation, unexpected database reads), and mitigation recommendations (use external credential managers and EDR policies targeting these behaviors).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
