Backdoor Using Twitter For Command & Control
ID: 364e5cb0-a435-5d25-8958-8ddcb29692ec
STIX ID: report--364e5cb0-a435-5d25-8958-8ddcb29692ec
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using DLL injection and the IElevator COM interface), Opera/Vivaldi (DPAPI), and Firefox (NSS). The README documents operational evasion features, usage examples, attack scenarios demonstrating rapid cloud account takeover potential, and detection/mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
