China taking control of it’s own DNS servers
ID: d94e21b1-f1a4-5350-b5c2-29c4f3eaf858
STIX ID: report--d94e21b1-f1a4-5350-b5c2-29c4f3eaf858
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool (available as precompiled binaries) that targets Chromium- and Gecko-based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill, history and bookmarks. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process and using the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection). The report details usage, attack scenarios, detection opportunities, and mitigations, and frames the tool as relevant for red-team and adversary simulation to evaluate exposure of SaaS and developer credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
