Russian Elcomsoft Finds Backdoor in Quicken Passwords
ID: 4e5a8f18-73d1-51fd-96d8-8b87ce22afae
STIX ID: report--4e5a8f18-73d1-51fd-96d8-8b87ce22afae
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation tool that harvests browser-stored credentials and session tokens across Chromium-based and Gecko-based browsers by using techniques including Early Bird APC DLL injection into headless Chromium to bypass App‑Bound Encryption via the IElevator COM interface, DPAPI/NSS decryption for other browsers, and several evasion measures; extracted data includes saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history, and output is written as structured JSON for red-team use and testing detection controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
