New Rootkits Infecting the MBR
ID: b16127f0-4e43-5310-ab00-255639325e11
STIX ID: report--b16127f0-4e43-5310-ab00-255639325e11
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved logins, session cookies, OAuth tokens, credit cards, autofill and history) from major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS models for other browsers, and includes numerous operational evasion features; the tool is positioned for red-team use but can be abused by adversaries to enable account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
