Large Scale Botnet Brute Force Password Cracking Against WordPress Sites
ID: cf729ffa-860c-5c67-ae1c-18eaa33bf8c6
STIX ID: report--cf729ffa-860c-5c67-ae1c-18eaa33bf8c6
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser‑stored secrets (cookies, saved passwords, OAuth refresh tokens, credit cards, autofill, history) from Chromium‑based browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi) and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt encryption keys, handles DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is intended for red team/assumed‑breach use while also being directly useful to attackers seeking rapid lateral movement and cloud account takeover; detection focuses on anomalous headless browser instantiation, process injection, IElevator calls from non-browser contexts, and non‑browser reads of browser SQLite databases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
