Hotmail Always-On Encryption Breaks Microsoft’s Own Apps
ID: 2ecd7f0b-99ec-51fb-93f9-3710d7d4551c
STIX ID: report--2ecd7f0b-99ec-51fb-93f9-3710d7d4551c
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; DPAPI and NSS decryption methods are used for other browsers. The repo and report describe usage, supported browsers, extracted data types, evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), detection opportunities, and mitigation recommendations for enterprise defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
