Shadowserver Battles the Botnets
ID: 6e0f7c01-4c49-5e6e-8709-9f6838339db4
STIX ID: report--6e0f7c01-4c49-5e6e-8709-9f6838339db4
Feed Name: Darknet
DumpBrowserSecrets is a publicly available Windows post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox by bypassing App‑Bound Encryption (via headless Chromium + injected DLL and IElevator COM), using DPAPI extraction, and NSS decryption for Firefox. The report details its operation, evasion techniques, supported browsers and data types, an example attack scenario, detection opportunities, and mitigation recommendations to evaluate enterprise exposure to browser-based credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
