logo

Conficker Finally Awakes & Dumps Payload

ID: d8836045-8d64-502f-a1b9-6f8a2dd84739

STIX ID: report--d8836045-8d64-502f-a1b9-6f8a2dd84739

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-04-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based (Chrome, Edge, Brave, Opera-family, Vivaldi) and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report details usage, extracted output (JSON), operational scenarios, detection opportunities (unexpected process injection, headless browser instantiation, reads of browser SQLite DBs by non-browser processes, IElevator calls), and mitigations such as using dedicated credential managers and EDR rules targeting the described behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.