Kyrgyzstan Taken Offline by Huge Denial of Service Attack
ID: 2c745e97-2074-5e09-8e58-d967636629ad
STIX ID: report--2c745e97-2074-5e09-8e58-d967636629ad
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from major Chromium-based and Firefox browsers; it bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL using Early Bird APC to call the IElevator COM interface, and uses DPAPI/NSS methods for other browsers. The report describes the tool's components, supported browsers, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), operational usage examples, detection opportunities (injection, IElevator calls, unusual SQLite reads), and mitigation recommendations (use of external credential managers and EDRs monitoring IElevator/headless browser behavior).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
