AI-Powered Cybercrime in 2025 – The Dark Web’s New Arms Race
ID: eae8fcd2-df51-5698-9284-b57be56e4917
STIX ID: report--eae8fcd2-df51-5698-9284-b57be56e4917
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt encryption keys, and includes multiple operational evasion techniques; the tool outputs structured JSON containing cookies, OAuth refresh tokens, saved logins, credit card data, autofill entries and history, making it a high-risk capability for lateral movement and cloud account takeover if used by an attacker.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
