Malware Authors Jumping on the Obama Bandwagon
ID: 464ed8b4-f099-5166-ae07-998af6ab99e8
STIX ID: report--464ed8b4-f099-5166-ae07-998af6ab99e8
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials, cookies, OAuth tokens, credit cards, autofill data, and history from major browsers by bypassing App‑Bound Encryption (Chrome/Edge/Brave), DPAPI (Opera/Vivaldi), and NSS (Firefox). The report details the tool's architecture (an executable plus injected DLL), sophisticated injection and evasion techniques (Early Bird APC injection, IElevator COM usage, PPID/argument spoofing, API hashing, custom SQLite parser), supported data types, attack scenarios for lateral movement and SaaS account takeover, and recommended detection and mitigation strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
