logo

Koobface Worm Variant Hits Facebook

ID: 49b13e18-52c7-51bb-93f7-9b2cdd75b092

STIX ID: report--49b13e18-52c7-51bb-93f7-9b2cdd75b092

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-03-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts browser‑stored secrets from Chromium‑based and Firefox browsers by bypassing App‑Bound Encryption (via headless Chromium + Early Bird APC DLL injection and the IElevator COM interface), handling DPAPI and NSS decryption as needed, and emitting structured JSON output; it includes multiple evasion techniques to reduce EDR detection and is intended for red‑team assumed‑breach assessments but represents a high‑impact capability against compromised developer workstations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.