Smart Trojan Targets eBay Users
ID: fac4d839-2605-55ae-ac16-069cc993cccb
STIX ID: report--fac4d839-2605-55ae-ac16-069cc993cccb
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium‑based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers; it bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI/NSS for other browsers, includes multiple evasion features, and outputs structured JSON for red‑team or adversary use — detection focuses on unusual headless browser processes, non‑browser reads of browser SQLite files, and IElevator COM calls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
