logo

Serious Exploit in Windows Media Player (WMP)

ID: 04aa69a2-5b7b-5465-827d-627098376d5c

STIX ID: report--04aa69a2-5b7b-5465-827d-627098376d5c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-01-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool for Windows that extracts browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from major Chromium-based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, contains operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is positioned for red-team testing while posing a significant risk if misused by threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.