logo

Malvertising and TDS Cloaking Tactics Uncovered

ID: 6c2438d5-5726-5792-b014-9cc1321ab89f

STIX ID: report--6c2438d5-5726-5792-b014-9cc1321ab89f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-07-02

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox on Windows. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI or NSS-protected keys for other browsers, and writes structured JSON output for red-team use; the report covers technical operation, evasion features, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.