Energizer Duo USB Battery Charger Software Has Backdoor Trojan
ID: af9c3683-9627-5393-b5d5-e292e751e7fb
STIX ID: report--af9c3683-9627-5393-b5d5-e292e751e7fb
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Firefox) to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface (Early Bird APC injection), handles DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red team or attacker use; the report covers attack scenarios, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
