Vodafone Spain Distributing Mariposa Malware
ID: 2ba9ee4d-d4cf-5ed8-b7f8-b8b5fa678793
STIX ID: report--2ba9ee4d-d4cf-5ed8-b7f8-b8b5fa678793
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome App-Bound Encryption by spawning a headless Chromium, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt keys (DPAPI and NSS handled separately), writes structured JSON output, and includes multiple evasion techniques—intended for red-team assumed-breach testing but usable by adversaries to enable lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
