logo

No BEAST Fix From Microsoft In December Patch Tuesday

ID: 0eab843c-c8e3-5b51-b61a-df63043ae35b

STIX ID: report--0eab843c-c8e3-5b51-b61a-df63043ae35b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-12-15

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium spawning with Early Bird APC DLL injection and the IElevator COM interface to decrypt app_bound_encrypted_key, includes multiple operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red‑team utility for assessing credential exposure, with recommended detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.