logo

Hackers Exploiting Unpatched DirectX Bug With Quicktime

ID: 1e5ba7f1-d58f-54f2-b567-1059c78121c3

STIX ID: report--1e5ba7f1-d58f-54f2-b567-1059c78121c3

Feed Name: Darknet

Threat Score
70/100

Date Published: 2009-06-01

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that targets Chromium-based (Chrome, Edge, Brave, Opera-family, Vivaldi) and Firefox browsers to extract saved credentials, cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. The tool implements an App-Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface for decryption, and uses DPAPI or NSS methods for other browsers; it includes operational evasion features and is intended for red-team/assumed-breach testing while representing a high-risk capability if used by attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.