Russian Cyber-Crime Market Doubled In 2011
ID: 82201137-b4cb-556e-9610-b9b65ce95454
STIX ID: report--82201137-b4cb-556e-9610-b9b65ce95454
Feed Name: Darknet
This report reviews DumpBrowserSecrets, a publicly available post-exploitation tool that harvests browser-stored credentials, cookies, OAuth refresh tokens, credit card data, autofill entries, and history from Chrome/Edge/Brave (App-Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It explains the technical approach—spawning a headless Chromium, performing Early Bird APC DLL injection to use the IElevator COM interface to decrypt app-bound keys, local decryption of SQLite/JSON stores, and evasion techniques—and provides use cases, detection opportunities, and mitigation advice for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
