logo

Viber Vulnerable To Man In The Middle Attack (MITM)

ID: 35005f68-03dd-5fb1-aa74-4dd74def346c

STIX ID: report--35005f68-03dd-5fb1-aa74-4dd74def346c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-04-24

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based browsers and Firefox. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium instance and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; Opera-family browsers are handled via DPAPI retrieval and Firefox via NSS decryption. The report describes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), output formats, attack scenarios (rapid credential extraction enabling cloud account takeover and lateral movement), detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.