FBI Investigating Gawker Media User Database Password Ownage
ID: 34acd078-a8f3-5c34-9ae4-4232a56e7e05
STIX ID: report--34acd078-a8f3-5c34-9ae4-4232a56e7e05
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, and uses DPAPI/NSS procedures for other browsers; the tool includes operational evasion features, writes structured JSON output, and includes detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
