Spamhaus & e360 Battle is Heating Up
ID: cd928edd-0a61-5150-b15d-5bea1465ee81
STIX ID: report--cd928edd-0a61-5150-b15d-5bea1465ee81
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill, and browsing history. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS models for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The tool is positioned for red-team/assumed-breach use but represents a realistic and technically capable infostealer that can enable cloud account takeover and lateral movement; the report includes detection opportunities and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
