French Company Intego Release First iPhone Malware Scanner
ID: adb56eb6-dc74-552d-a102-da4afbe22cd6
STIX ID: report--adb56eb6-dc74-552d-a102-da4afbe22cd6
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that targets Chromium‑based and Gecko browsers to extract saved credentials, session cookies, OAuth refresh tokens, autofill data, credit card details and browsing history. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes evasion techniques for EDR, and outputs structured JSON for red‑team use; recommended mitigations include monitoring IElevator calls, detecting unexpected headless browser processes and avoiding browser‑stored credentials via dedicated password managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
