MSN Password Stealing Trojan Becomes Public
ID: 7d473783-3c9b-5d1a-8e9e-6698166b95c2
STIX ID: report--7d473783-3c9b-5d1a-8e9e-6698166b95c2
Feed Name: Darknet
DumpBrowserSecrets is a publicly distributed post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It implements an App‑Bound Encryption bypass for Chromium‑based browsers by injecting a DLL into a spawned headless Chromium process to call the IElevator COM interface and decrypt the app_bound_encrypted_key; for DPAPI‑based browsers and Firefox it uses appropriate local decryption methods. The report documents extracted data types (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history), operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), a realistic attack scenario against developer workstations, and recommended detection and mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
