Microsoft Opens the Gates to Hack Their Web Services
ID: 17b7d582-1378-5301-a047-235d9c53100c
STIX ID: report--17b7d582-1378-5301-a047-235d9c53100c
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation credential‑harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox) to extract passwords, cookies, OAuth tokens, credit cards, autofill data and history. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, includes DPAPI/NSS handling for other browsers, and implements evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication). The report covers installation, usage examples, detection opportunities (process injection, IElevator calls, non-browser reads of browser SQLite DBs), and mitigation recommendations such as using dedicated credential managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
