Virus Variant Extorts You by Encrypting Your Files
ID: 806c523e-4bb4-5718-8e49-58558d989206
STIX ID: report--806c523e-4bb4-5718-8e49-58558d989206
Feed Name: Darknet
Threat Score
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera, Vivaldi and Firefox by bypassing App‑Bound Encryption (via DLL injection and the IElevator COM interface), DPAPI, and NSS protections; it outputs structured JSON and includes multiple evasion features intended to survive EDR scrutiny, making it useful for red teams and a high-risk capability if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
