logo

Russian Cyber-Crime Market Doubled In 2011

ID: 82201137-b4cb-556e-9610-b9b65ce95454

STIX ID: report--82201137-b4cb-556e-9610-b9b65ce95454

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-04-30

Date Updated: 2026-05-08

...
...

This report reviews DumpBrowserSecrets, a publicly available post-exploitation tool that harvests browser-stored credentials, cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chrome/Edge/Brave (App-Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It explains the technical approach—spawning a headless Chromium, performing Early Bird APC DLL injection to use the IElevator COM interface to decrypt app-bound keys, local decryption of SQLite/JSON stores, and evasion techniques—and provides use cases, detection opportunities, and mitigation advice for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.