Pirated ‘Watch Dogs’ Game Made A Bitcoin Mining Botnet
ID: aa8cc7b1-ab77-5b2a-a8a7-066aa917d3d9
STIX ID: report--aa8cc7b1-ab77-5b2a-a8a7-066aa917d3d9
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that extracts browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave with App‑Bound Encryption, Opera/Vivaldi using DPAPI, and Firefox using NSS). It uses a compiled executable plus a DLL injected via Early Bird APC into a headless Chromium process to bypass App‑Bound Encryption through the IElevator COM interface, includes evasion techniques to reduce EDR detection, outputs structured JSON of recovered secrets, and is positioned primarily for red‑team/assumed‑breach testing while also representing a high‑value capability for adversaries seeking lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
