Facebook Used By Whitewell Trojan To Communicate
ID: f7d2b29c-060b-5f12-8a97-9600f9a7417e
STIX ID: report--f7d2b29c-060b-5f12-8a97-9600f9a7417e
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chrome, Edge, Brave, Opera, Vivaldi, and Firefox by using DLL injection into a headless Chromium process to bypass App‑Bound Encryption (via the IElevator COM interface) and by extracting DPAPI/NSS‑protected data; it includes multiple evasion techniques, outputs structured JSON, and is intended for red team assumed‑breach testing but presents substantive misuse risk if adopted by threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
