Hackers Targeting Xbox Live Players with DoS Attacks
ID: 4d9e9f71-2368-524f-bbb5-b2ed77f235bc
STIX ID: report--4d9e9f71-2368-524f-bbb5-b2ed77f235bc
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation tool that automates extraction of browser‑stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from major Windows browsers. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox. The README documents usage, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), a short attack scenario demonstrating credential theft and session replay, and detection/mitigation advice for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
