Twitter DM Phishing Scam
ID: 55e6ba38-98ca-540b-a36e-4bca8782a8b5
STIX ID: report--55e6ba38-98ca-540b-a36e-4bca8782a8b5
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using a headless Chromium process and IElevator DLL injection), Opera/Vivaldi (DPAPI), and Firefox (NSS). The README explains deployment (precompiled binaries or build from source), evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), extracted outputs (JSON per browser), a short attack scenario showing rapid credential extraction for cloud account takeover, and detection/mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
