logo

Smart Trojan Targets eBay Users

ID: fac4d839-2605-55ae-ac16-069cc993cccb

STIX ID: report--fac4d839-2605-55ae-ac16-069cc993cccb

Feed Name: Darknet

Threat Score
78/100

Date Published: 2007-04-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers; it bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI/NSS for other browsers, includes multiple evasion features, and outputs structured JSON for red‑team or adversary use — detection focuses on unusual headless browser processes, non‑browser reads of browser SQLite files, and IElevator COM calls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.