German Federal Trojan (0zapftis/Bundestrojaner) Eavesdrops On Skype, IE, Firefox, MSN Messenger & More
ID: 314de47c-f17a-5307-88b0-5d2f92b4defc
STIX ID: report--314de47c-f17a-5307-88b0-5d2f92b4defc
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from major Chromium‑based and Firefox browsers on Windows. It bypasses App‑Bound Encryption in modern Chromium builds by injecting a DLL into a headless browser process to use the IElevator COM interface, handles DPAPI and NSS encrypted stores, includes multiple EDR‑evasion techniques, and outputs structured JSON for rapid credential reuse—making it highly relevant for red teams and malicious actors seeking cloud and SaaS account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
