logo

Mac OS X Ransomware KeRanger Is Linux Encoder Trojan

ID: 3e112d64-0bd6-5ff6-916f-9d6884360a2a

STIX ID: report--3e112d64-0bd6-5ff6-916f-9d6884360a2a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-03-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential-harvesting tool (publicly distributed) that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major Chromium-based and Firefox browsers on Windows. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by injecting a DLL into a headless Chromium process to call the IElevator COM interface, uses DPAPI/NSS handling for other browsers, includes multiple evasion techniques, and outputs structured JSON for red‑team or adversary use; the report covers usage, attack scenarios, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.