Twitter Hack Spreads P*rn Trojan
ID: 771a8b40-9a01-5930-9eb2-28d3e89d7f68
STIX ID: report--771a8b40-9a01-5930-9eb2-28d3e89d7f68
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chrome, Edge, Brave, Opera-family browsers and Firefox. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt encryption keys, includes DPAPI and NSS handling for other browsers, and incorporates evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report details usage, attack scenarios (rapid credential extraction enabling cloud account takeover and lateral movement), detection indicators, and mitigation recommendations such as removing browser-stored secrets and monitoring IElevator/headless browser activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
