WordPress 2.8.3 Admin Reset Exploit
ID: 360895a6-9cb2-5919-a8a1-1576fe6dc660
STIX ID: report--360895a6-9cb2-5919-a8a1-1576fe6dc660
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium-based browsers and Firefox. It implements a sophisticated App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt app_bound_encrypted_key, and uses DPAPI or NSS methods for other browsers; the tool includes operational evasion features and outputs structured JSON for red‑team use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
