Super Powered Malware Sandwiches Found In The Wild
ID: ecd18588-d9ae-5009-8065-b65f1dcc8893
STIX ID: report--ecd18588-d9ae-5009-8065-b65f1dcc8893
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to use the IElevator COM interface to decrypt keys, handles DPAPI and NSS decryption for other browsers, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is intended for red-team/assumed-breach testing while posing a significant credential-theft risk if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
