Fake CNN Site From Phishing E-mail Serves Trojan
ID: d7bbd54f-b603-5789-ac0e-6fa95b063893
STIX ID: report--d7bbd54f-b603-5789-ac0e-6fa95b063893
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials (passwords, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chromium- and Gecko-based browsers by using headless Chromium instantiation, Early Bird APC DLL injection and the IElevator COM interface to bypass App-Bound Encryption (Chrome/Edge/Brave), plus DPAPI and NSS handling for other browsers; it is positioned for red-team use but presents a high-risk credential-exfiltration capability for real-world attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
