logo

Cisco Vulnerability Given ‘Write Once, Run Anywhere’ Treatement

ID: 23bfbd64-df72-59c0-8236-50656d9f80f6

STIX ID: report--23bfbd64-df72-59c0-8236-50656d9f80f6

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-01-07

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, payment data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC injection to call the IElevator COM interface, and returns decrypted keys to decrypt on-disk SQLite/JSON stores; Firefox logins are handled via NSS decryption. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), writes structured JSON output, and is intended for red-team/assumed-breach use; the report also outlines detection opportunities and mitigations such as monitoring IElevator usage and moving secrets to external credential managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.