Trojan for the Word Vulnerability in the Wild
ID: 2d99abdb-9e75-5fe3-8cb6-6557ff2ab650
STIX ID: report--2d99abdb-9e75-5fe3-8cb6-6557ff2ab650
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and tokens from major Windows browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC + IElevator COM interface) to decrypt app-bound keys, includes operational evasion features, outputs structured JSON, and is intended for red-team and assumed-breach testing but represents a realistic credential-theft threat for enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
