Malware Researchers Discover Rootkit HKTL-BRUDEVIC Similar to Sony CD Malware
ID: 47b6c187-3dfe-5020-900a-e2800d37d522
STIX ID: report--47b6c187-3dfe-5020-900a-e2800d37d522
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that extracts browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, and history) from Chromium-based browsers and Firefox. It uses headless Chromium process spawning and Early Bird APC DLL injection to leverage the IElevator COM interface and bypass Chrome's App-Bound Encryption, handles DPAPI and NSS decryption for other browsers, includes operational evasion features, and outputs structured JSON for red-team use; the report also covers attack scenarios, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
