Targeted Phishing Attacks Carried Out On Gmail
ID: 56cc6fc1-391f-5b7c-b20e-46661a94fd56
STIX ID: report--56cc6fc1-391f-5b7c-b20e-46661a94fd56
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chromium-based and Gecko-based browsers by using DLL injection (Early Bird APC) into a headless Chromium process to invoke the IElevator COM interface and decrypt App-Bound Encryption keys, or by retrieving DPAPI/NSS keys where applicable; the tool includes evasion features, outputs structured JSON, and is positioned for red-team assumed-breach testing but could be repurposed by attackers to enable rapid cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
