logo

Sony Digital Certs Being Used To Sign Malware

ID: 4d9eb3fa-ccb7-5b73-ae9c-e7fed21522f9

STIX ID: report--4d9eb3fa-ccb7-5b73-ae9c-e7fed21522f9

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-12-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest browser-stored credentials and session tokens across major Chromium-based browsers and Firefox. It uses Early Bird APC DLL injection into a headless Chromium process to invoke the IElevator COM interface and decrypt App-Bound Encryption keys (Chrome/Brave/Edge), retrieves DPAPI keys for Opera-family browsers, and uses NSS decryption for Firefox, producing structured JSON output of cookies, saved logins, OAuth tokens, credit cards, autofill data, and history; the report highlights evasion features, detection opportunities, and red-team use-cases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.