New Conficker Variant More Aggressive
ID: e6d2334a-0da2-5d06-9bae-f901fbda4e1e
STIX ID: report--e6d2334a-0da2-5d06-9bae-f901fbda4e1e
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that extracts browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera-family, Vivaldi and Firefox. It implements an App‑Bound Encryption bypass for modern Chromium builds by spawning a headless Chromium process and injecting a DLL via Early Bird APC to access the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes several evasion techniques, and is presented with usage, attack scenarios, detection opportunities, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
