Yahoo! Fined 35 Million USD For Late Disclosure Of Hack
ID: 2f4c6084-f45b-5a90-9af8-30eac1249c68
STIX ID: report--2f4c6084-f45b-5a90-9af8-30eac1249c68
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill and history) from major Windows browsers. It bypasses Chrome/Edge/Brave App-Bound Encryption by spawning a headless Chromium instance and injecting a DLL to call the IElevator COM interface, uses DPAPI for Opera-derived browsers and NSS decryption for Firefox, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool outputs structured JSON for red-team use and presents a fast path to SaaS/cloud account takeover and lateral movement on compromised developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
