Zeus-related Botnet Servers Taken Offline
ID: 57929922-01b8-5410-b9b0-9ccb4e6734bd
STIX ID: report--57929922-01b8-5410-b9b0-9ccb4e6734bd
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, employs DPAPI or NSS handling where applicable, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report documents usage, attack scenarios, detection opportunities (process injection, headless browser instantiation, reads of Login Data/Cookies/Web Data by non‑browser processes, IElevator calls), and mitigation recommendations such as using external credential managers and EDR rules that monitor IElevator calls and headless browser behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
