logo

Twitter Hack Spreads P*rn Trojan

ID: 771a8b40-9a01-5930-9eb2-28d3e89d7f68

STIX ID: report--771a8b40-9a01-5930-9eb2-28d3e89d7f68

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-06-24

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chrome, Edge, Brave, Opera-family browsers and Firefox. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt encryption keys, includes DPAPI and NSS handling for other browsers, and incorporates evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report details usage, attack scenarios (rapid credential extraction enabling cloud account takeover and lateral movement), detection indicators, and mitigation recommendations such as removing browser-stored secrets and monitoring IElevator/headless browser activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.