logo

Linux Backdoor Fokirtor Injects Traffic Into SSH Protocol

ID: 6d04a5f7-d28a-5a35-8ce2-c37304b08752

STIX ID: report--6d04a5f7-d28a-5a35-8ce2-c37304b08752

Feed Name: Darknet

Threat Score
75/100

Date Published: 2013-11-15

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential extraction tool that targets Chromium‑based and Firefox browsers on Windows to recover saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history. It bypasses Chrome App‑Bound Encryption (via spawning a headless Chromium process and DLL injection using Early Bird APC to call the IElevator COM interface), handles DPAPI for other Chromium forks, and uses NSS decryption for Firefox; the tool includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red‑team or offensive use, enabling rapid account takeover and lateral movement in assumed‑breach scenarios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.