logo

Private Signed Certificate From Malaysian Government Used To Spread Malware

ID: a1bbb59f-b361-5c83-8485-445765c11fe2

STIX ID: report--a1bbb59f-b361-5c83-8485-445765c11fe2

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-11-15

Date Updated: 2026-05-08

...
...

**DumpBrowserSecrets — Browser Credential Harvesting with App‑Bound Encryption Bypass**: This report analyzes DumpBrowserSecrets, a publicly available post‑exploitation tool that extracts credentials and session material from Chromium‑based and Gecko‑based browsers. It details how the tool bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report covers supported browsers and extracted data types, usage examples, detection opportunities, mitigations, and red‑team relevance for assessing SaaS and developer endpoint exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.