Brittany Murphy Dies & Scareware Scammers Strike
ID: ef470590-bdf9-585e-b5f2-b5be20c89333
STIX ID: report--ef470590-bdf9-585e-b5f2-b5be20c89333
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via an App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It combines a compiled executable and a DLL injected into a headless Chromium process to decrypt app-bound keys, extracts cookies, saved logins, OAuth refresh tokens, credit card data and history into JSON, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report outlines attack scenarios, detection opportunities (process injection, IElevator COM calls, reads of Login Data/Cookies/Web Data by non-browser processes) and mitigations such as using external credential managers and EDR monitoring of the IElevator interface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
