Browser Credential Dumping
ID: aa2c4df1-bfac-5f26-a841-88bfd1899ff9
STIX ID: report--aa2c4df1-bfac-5f26-a841-88bfd1899ff9
Feed Name: ReliaQuest Blog
ReliaQuest examines the growing use of browser credential dumping—where threat actors extract saved browser credentials and cookies on Windows and macOS—highlighting mechanisms, common storage locations, tools (open-source stealers, Cobalt Strike/Metasploit modules, infostealers like RedLine and Lumma), a Q4 2023 LummaC2 case study with IoCs (e.g., IP 188.114.96.3 and domain ebalkayiu.fun and Chrome/Edge/Login Data paths), observed prevalence (21% of credential-access incidents) and market signals (201% increase in infostealer logs), and prescribes detections and mitigations (EDR/file access monitoring, block browser-stored credentials, MFA, password managers, AppLocker/MDM, strict allowlists, restricted command usage).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
