Malvertising and TDS Cloaking Tactics Uncovered
ID: 6c2438d5-5726-5792-b014-9cc1321ab89f
STIX ID: report--6c2438d5-5726-5792-b014-9cc1321ab89f
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox on Windows. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI or NSS-protected keys for other browsers, and writes structured JSON output for red-team use; the report covers technical operation, evasion features, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
