logo

NSA Large Scale TURBINE Malware Also Target Sysadmins

ID: 3a714dd1-5ec8-51a2-9cc2-7201f6782965

STIX ID: report--3a714dd1-5ec8-51a2-9cc2-7201f6782965

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-03-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers on Windows. It uses DLL injection into a headless Chromium process and the IElevator COM interface to decrypt App-Bound Encryption keys (Chrome/Edge/Brave), retrieves DPAPI keys for Opera-family browsers, and handles Firefox via NSS decryption; the report also covers evasion features, operational usage, detection indicators, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.