logo

Hotmail Always-On Encryption Breaks Microsoft’s Own Apps

ID: 2ecd7f0b-99ec-51fb-93f9-3710d7d4551c

STIX ID: report--2ecd7f0b-99ec-51fb-93f9-3710d7d4551c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-11-09

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; DPAPI and NSS decryption methods are used for other browsers. The repo and report describe usage, supported browsers, extracted data types, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), detection opportunities, and mitigation recommendations for enterprise defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.