Conficker (AKA Downadup or Kido) Infections Skyrocket To An Estimate 9 Million
ID: fa1c0747-dad6-5f1b-9c9b-d4459e56c86f
STIX ID: report--fa1c0747-dad6-5f1b-9c9b-d4459e56c86f
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool for extracting browser-stored credentials and session material from major Chromium-based and Firefox browsers. It bypasses Chrome’s App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, retrieves DPAPI keys for some Chromium forks, and directly handles Firefox NSS-protected logins; the tool outputs structured JSON, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parsing), and is presented as a red-team utility with detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
