Doubleclick Involved in Malware Distribution
ID: 812f37ad-ff6a-5d2d-9f54-022e6d0fd5dd
STIX ID: report--812f37ad-ff6a-5d2d-9f54-022e6d0fd5dd
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool (designed for red teams) that harvests browser-stored secrets across Chrome/Edge/Brave (App‑Bound Encryption bypass via injected DLL and IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It outputs structured JSON of cookies, saved logins, OAuth tokens, credit cards, autofill data and history, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, file-lock bypass), and the report covers usage, detection opportunities, mitigations, and an attack scenario demonstrating rapid credential extraction and cloud account takeover risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
