China Reports Millions Of Conficker Infections
ID: 4ec48369-e56d-54cc-aa73-c5d27344d6fd
STIX ID: report--4ec48369-e56d-54cc-aa73-c5d27344d6fd
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts credentials and session data from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) by decrypting App‑Bound Encryption or DPAPI/NSS‑protected stores. It uses a two‑component approach (an executable and injected DLL) with Early Bird APC DLL injection into a headless Chromium process to call the IElevator COM interface and retrieve encryption keys, then parses browser SQLite/JSON stores to output structured JSON containing cookies, OAuth tokens, saved logins, credit cards, autofill data, history, and bookmarks; the report details operational evasion features, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
