logo

DNS DDoS Attack Takes Down China Internet

ID: 3decbfa2-0ff1-5605-b14c-45260796ceb0

STIX ID: report--3decbfa2-0ff1-5605-b14c-45260796ceb0

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-05-22

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly described post-exploitation tool that harvests browser-stored credentials and session material from major Windows browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The report documents the tool's architecture (an executable plus an injected DLL using Early Bird APC to call the IElevator COM interface), extracted data types (cookies, OAuth refresh tokens, saved logins, credit cards, autofill, history), operational evasion features, usage examples for red-team/assumed-breach scenarios, and recommended detection and mitigation approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.