LiveJournal Advert Installs Malware
ID: f0d1c969-bf25-5fe9-9967-0c55337ed211
STIX ID: report--f0d1c969-bf25-5fe9-9967-0c55337ed211
Feed Name: Darknet
**DumpBrowserSecrets** is a Windows post‑exploitation tool that harvests browser‑stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill and history) from Chrome/Edge/Brave (App‑Bound Encryption bypass via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It documents implementation details (headless Chromium spawn, Early Bird APC DLL injection, named‑pipe IPC, custom SQLite parser), provides usage and attack scenarios for red teams, and outlines detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
