NotPetya Ransomeware Wreaking Havoc
ID: 328f3f87-e2c0-594e-9eb2-2372d0bec6b8
STIX ID: report--328f3f87-e2c0-594e-9eb2-2372d0bec6b8
Feed Name: Darknet
# Executive Summary DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based browsers and Firefox by spawning a headless browser, injecting a DLL to bypass App-Bound Encryption (IElevator COM) or retrieving DPAPI/NSS keys, parsing SQLite/JSON stores, and exporting structured JSON; it includes operational evasion features and is positioned for red-team use but represents a high-risk capability for credential theft and cloud account takeover if used maliciously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
