Serious Exploit in Windows Media Player (WMP)
ID: 04aa69a2-5b7b-5465-827d-627098376d5c
STIX ID: report--04aa69a2-5b7b-5465-827d-627098376d5c
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool for Windows that extracts browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from major Chromium-based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, contains operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is positioned for red-team testing while posing a significant risk if misused by threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
