The Tale of a Real Malaysian E-mail Spammer Exposed
ID: b24cecf2-674d-5126-9dbd-037a259ab259
STIX ID: report--b24cecf2-674d-5126-9dbd-037a259ab259
Feed Name: Darknet
This report analyzes DumpBrowserSecrets, a publicly released post‑exploitation tool that harvests browser‑stored secrets (saved logins, cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chromium‑based and Gecko browsers. It explains the App‑Bound Encryption bypass for Chrome/Edge/Brave via DLL injection into a headless Chromium process using the IElevator COM interface, DPAPI and NSS handling for other browsers, evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), output format, use cases for red teams, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
