logo

Facebook Used By Whitewell Trojan To Communicate

ID: f7d2b29c-060b-5f12-8a97-9600f9a7417e

STIX ID: report--f7d2b29c-060b-5f12-8a97-9600f9a7417e

Feed Name: Darknet

Threat Score
80/100

Date Published: 2009-11-08

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from Chrome, Edge, Brave, Opera, Vivaldi, and Firefox by using DLL injection into a headless Chromium process to bypass App‑Bound Encryption (via the IElevator COM interface) and by extracting DPAPI/NSS‑protected data; it includes multiple evasion techniques, outputs structured JSON, and is intended for red team assumed‑breach testing but presents substantive misuse risk if adopted by threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.