Botnets and Phishing Numbers Increasing Despite Crackdown
ID: 56abd152-5418-51ea-92ba-6a909f5724f1
STIX ID: report--56abd152-5418-51ea-92ba-6a909f5724f1
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts browser‑stored credentials and tokens from Chromium‑based browsers (including App‑Bound Encryption bypass) and Firefox; the report details its architecture (an executable plus a DLL), DLL injection via Early Bird APC into a headless Chromium process to use the IElevator COM interface to decrypt app_bound_encrypted_key, the data types recovered (cookies, saved logins, OAuth tokens, credit cards, autofill, history), evasion techniques, an attack scenario, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
