Tabnapping Attack On The Increase
ID: f92e5750-98dd-5c24-8c9d-bf87a18efcb0
STIX ID: report--f92e5750-98dd-5c24-8c9d-bf87a18efcb0
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The tool uses a headless Chromium spawn with Early Bird APC DLL injection to leverage the IElevator COM interface and decrypt app_bound_encrypted_key, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), writes structured JSON output, and is intended for red-team assumed-breach testing though it carries obvious abuse potential for credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
