Microsoft Investigates IE CSS Cross-Origin Theft Vulnerability
ID: 13f84da4-02b6-51ad-b858-d0eddb06a59e
STIX ID: report--13f84da4-02b6-51ad-b858-d0eddb06a59e
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that extracts credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). The tool uses headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to decrypt app_bound_encrypted_key for Chromium-based browsers, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is intended for red-team/assumed‑breach testing but represents a high‑risk capability for credential theft and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
