Microsoft Confirms Windows Zero Day Bug In Shortcut Files
ID: 20cac8b8-2641-53fb-9ed1-c1ff8a8b437d
STIX ID: report--20cac8b8-2641-53fb-9ed1-c1ff8a8b437d
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium‑based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It uses a headless Chromium spawn plus Early Bird APC DLL injection to leverage the IElevator COM interface and decrypt App‑Bound Encryption keys (Chrome 127+), handles DPAPI and NSS decryption where applicable, includes multiple evasion techniques, outputs structured JSON, and is positioned for red‑team/assumed‑breach testing and detection validation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
