No BEAST Fix From Microsoft In December Patch Tuesday
ID: 0eab843c-c8e3-5b51-b61a-df63043ae35b
STIX ID: report--0eab843c-c8e3-5b51-b61a-df63043ae35b
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium spawning with Early Bird APC DLL injection and the IElevator COM interface to decrypt app_bound_encrypted_key, includes multiple operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is presented as a red‑team utility for assessing credential exposure, with recommended detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
