logo

Fake E-commerce Platforms as Attack Vectors & Threats in 2025

ID: 3d81643a-77a1-566c-8bda-1ad5ca375719

STIX ID: report--3d81643a-77a1-566c-8bda-1ad5ca375719

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (Windows executable plus a DLL) that extracts saved logins, cookies, OAuth tokens, credit cards, autofill data and history from Chrome/Edge/Brave (App‑Bound Encryption bypass via IElevator), Opera/Vivaldi (DPAPI), and Firefox (NSS). The report covers architecture (Early Bird APC DLL injection into headless Chromium to decrypt app_bound_encrypted_key, local SQLite parsing, DPAPI/NSS handling), operational evasion features, example attack usage, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.