Federal Authorities Have Seized More Than $143 Million USD Of Fake Network Equipment
ID: 33f0ab73-02e6-5449-8f56-abbae4786521
STIX ID: report--33f0ab73-02e6-5449-8f56-abbae4786521
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks) from major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), writes structured JSON output, and is intended for red-team/assumed-breach testing though it raises substantive real-world abuse risk if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
