McAfee Seeds Mac Virus Threat FUD
ID: 85b7f7aa-2f19-5519-875e-a7add0d54c6e
STIX ID: report--85b7f7aa-2f19-5519-875e-a7add0d54c6e
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool (published by Maldev Academy) that extracts saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and history from major Windows browsers. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt the app_bound_encrypted_key, uses DPAPI for Opera/Vivaldi, and NSS decryption for Firefox; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection) and outputs structured JSON suitable for red‑team or malicious use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
