logo

Cafepress.com Under Heavy DDoS Attack

ID: 8743b3f9-f8cc-5ccf-a68b-117e4dac242b

STIX ID: report--8743b3f9-f8cc-5ccf-a68b-117e4dac242b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-02-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card details, autofill data, and browsing history from major browsers; it uses DLL injection (Early Bird APC) into a spawned headless Chromium to leverage the IElevator COM interface and decrypt App‑Bound Encryption keys for Chrome/Edge/Brave, retrieves DPAPI keys for Opera/Vivaldi, and handles Firefox NSS decryption directly. The report documents the tool's architecture, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), usage examples, attack scenarios, detection opportunities, and mitigation recommendations for enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.