Hackers Exploiting Unpatched DirectX Bug With Quicktime
ID: 1e5ba7f1-d58f-54f2-b567-1059c78121c3
STIX ID: report--1e5ba7f1-d58f-54f2-b567-1059c78121c3
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation browser credential-harvesting tool that targets Chromium-based (Chrome, Edge, Brave, Opera-family, Vivaldi) and Firefox browsers to extract saved credentials, cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks. The tool implements an App-Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface for decryption, and uses DPAPI or NSS methods for other browsers; it includes operational evasion features and is intended for red-team/assumed-breach testing while representing a high-risk capability if used by attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
