Twitter Being Used As Botnet Command Channel
ID: d423a0e2-69d5-5116-8acd-749bf36ee2f6
STIX ID: report--d423a0e2-69d5-5116-8acd-749bf36ee2f6
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from Chrome, Edge, Brave, Opera (including Opera GX and Vivaldi), and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key, retrieves DPAPI keys where applicable, and parses on-disk SQLite/JSON stores to output structured JSON; the tool includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser) and is positioned for red-team use but presents clear risk if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
