logo

South Korean Webhost Nayana Pays USD1 Million Ransom

ID: 81d639c1-6b7d-536a-93e2-cb1d6870cc84

STIX ID: report--81d639c1-6b7d-536a-93e2-cb1d6870cc84

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-06-21

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history) from Chrome/Edge/Brave (via App-Bound Encryption bypass using a headless Chromium process and IElevator COM), Opera/Vivaldi (DPAPI), and Firefox (NSS). The report details its injection and decryption techniques, operational evasion features, typical attack scenarios (developer workstation compromise and SaaS session takeover), detection vectors, and mitigation advice for enterprise defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.