Hackers Target Home Users for Cash
ID: 54e266dd-90e0-554a-84fb-47ca6439de58
STIX ID: report--54e266dd-90e0-554a-84fb-47ca6439de58
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and tokens from Windows hosts (Chrome/Edge/Brave via an App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + DLL injection (Early Bird APC) to decrypt app_bound_encrypted_key via the IElevator COM interface, extracts credentials from on-disk SQLite/JSON stores, includes multiple EDR-evasion features, and outputs structured JSON for red-team or malicious reuse — exposing a high-impact attack surface for cloud/SaaS account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
