Hacked Embassy Websites Delivering Malware
ID: b98c243a-3f97-544e-bef1-8583fef9ace7
STIX ID: report--b98c243a-3f97-544e-bef1-8583fef9ace7
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that extracts credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process and using the IElevator COM interface to decrypt encryption keys, supports DPAPI and NSS decryption for other browsers, and includes multiple evasion techniques to reduce detection by EDR. The tool outputs structured JSON of recovered secrets (cookies, OAuth tokens, saved logins, credit cards, autofill and history) and is positioned for red‑team and assumed‑breach engagements to demonstrate realistic credential exposure and potential cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
