Thousands Hooked by Malware from Big Sites
ID: ceea1f03-7524-53cd-b0d1-e05d398d478e
STIX ID: report--ceea1f03-7524-53cd-b0d1-e05d398d478e
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests browser‑stored credentials (passwords, cookies, OAuth tokens, credit cards, autofill and history) from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox; it implements an App‑Bound Encryption bypass for Chromium browsers by injecting a DLL into a headless Chromium process and using the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and incorporates evasion features to reduce EDR detection—making it a high‑impact credential theft capability useful for red teams and potentially abused by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
