Spreading Malware To Specific Tech Companies
ID: 8398ae60-73dd-5b6a-8049-738a0a5e1fb7
STIX ID: report--8398ae60-73dd-5b6a-8049-738a0a5e1fb7
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials (saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks) from major Chromium-based and Firefox browsers. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, and it handles DPAPI and NSS models for other browsers; the README documents usage, evasion techniques, attack scenarios, detection opportunities, and red-team use cases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
