Fake E-commerce Platforms as Attack Vectors & Threats in 2025
ID: 3d81643a-77a1-566c-8bda-1ad5ca375719
STIX ID: report--3d81643a-77a1-566c-8bda-1ad5ca375719
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (Windows executable plus a DLL) that extracts saved logins, cookies, OAuth tokens, credit cards, autofill data and history from Chrome/Edge/Brave (App‑Bound Encryption bypass via IElevator), Opera/Vivaldi (DPAPI), and Firefox (NSS). The report covers architecture (Early Bird APC DLL injection into headless Chromium to decrypt app_bound_encrypted_key, local SQLite parsing, DPAPI/NSS handling), operational evasion features, example attack usage, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
