WannaCry Ransomware Foiled By Domain Killswitch
ID: 76a6722c-4fdb-52af-8ec1-42b328251aa3
STIX ID: report--76a6722c-4fdb-52af-8ec1-42b328251aa3
Feed Name: Darknet
**DumpBrowserSecrets** is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based browsers and Firefox, including a specific bypass for Chrome's App-Bound Encryption via DLL injection into a headless Chromium process; the report describes its technical operation, supported browsers, evasion techniques, an attack scenario, and recommended detection and mitigation approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
