logo

Twitter DM Phishing Scam

ID: 55e6ba38-98ca-540b-a36e-4bca8782a8b5

STIX ID: report--55e6ba38-98ca-540b-a36e-4bca8782a8b5

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-09-24

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using a headless Chromium process and IElevator DLL injection), Opera/Vivaldi (DPAPI), and Firefox (NSS). The README explains deployment (precompiled binaries or build from source), evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), extracted outputs (JSON per browser), a short attack scenario showing rapid credential extraction for cloud account takeover, and detection/mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.