The Homeland Security Department Suffered More Than 800 Successful Hack Attacks
ID: 6d476dec-e1bc-516c-9255-8d5a5f78e1cf
STIX ID: report--6d476dec-e1bc-516c-9255-8d5a5f78e1cf
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill entries and browsing history from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface (and uses DPAPI or NSS decryption where appropriate), includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON for rapid misuse in cloud account takeover and lateral movement, and includes detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
