Yahoo! Spread Bitcoin Mining Botnet Malware Via Ads
ID: ea364057-5f03-5e7d-a709-41328c268b7f
STIX ID: report--ea364057-5f03-5e7d-a709-41328c268b7f
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool from Maldev Academy that targets Chromium- and Gecko-based browsers on Windows to extract saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes operational evasion features, writes structured JSON output, and is intended for red team/assumed-breach testing but represents a high-risk capability if abused by real attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
