logo

Spamhaus & e360 Battle is Heating Up

ID: cd928edd-0a61-5150-b15d-5bea1465ee81

STIX ID: report--cd928edd-0a61-5150-b15d-5bea1465ee81

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-11-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill, and browsing history. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS models for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The tool is positioned for red-team/assumed-breach use but represents a realistic and technically capable infostealer that can enable cloud account takeover and lateral movement; the report includes detection opportunities and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.