Security Researchers Discover 4 Million Strong 'Indestructible' Botnet
ID: dd923191-07e4-569e-b137-61edae721163
STIX ID: report--dd923191-07e4-569e-b137-61edae721163
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses modern protections — including Chrome's App-Bound Encryption via an IElevator COM interface attack executed inside a spawned headless Chromium process (DLL injected via Early Bird APC) — and extracts data from on-disk SQLite/JSON stores, returning structured JSON output. The report details implementation, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), operational usage in assumed-breach scenarios, detection opportunities (process injection, headless browser instantiation, IElevator calls, non-browser reads of browser DBs), and suggested mitigations such as using external credential managers and EDR rules targeting the described behaviours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
