Memhunter – Automated Memory Resident Malware Detection
ID: 6934dc24-54af-5aa8-a465-58e53f161f2c
STIX ID: report--6934dc24-54af-5aa8-a465-58e53f161f2c
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that targets Chromium-based and Gecko-based browsers to extract saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It uses DLL injection into a headless Chromium process and the IElevator COM interface to bypass App‑Bound Encryption (Chrome 127+), handles DPAPI and NSS decryption for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing). The report details usage, an operator attack scenario, detection opportunities (process injection, headless browser instantiation, IElevator calls, reads of Login Data/Cookies/Web Data by non-browser processes) and mitigations such as using dedicated password managers and EDR rules that monitor IElevator and headless browser behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
