logo

Vodafone Spain Distributing Mariposa Malware

ID: 2ba9ee4d-d4cf-5ed8-b7f8-b8b5fa678793

STIX ID: report--2ba9ee4d-d4cf-5ed8-b7f8-b8b5fa678793

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-03-18

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome App-Bound Encryption by spawning a headless Chromium, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt keys (DPAPI and NSS handled separately), writes structured JSON output, and includes multiple evasion techniques—intended for red-team assumed-breach testing but usable by adversaries to enable lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.