Oracle Java Cloud Service Vulnerabilities Publicly Disclosed
ID: 38256c95-0c62-5c5a-b29b-78288ef46b9c
STIX ID: report--38256c95-0c62-5c5a-b29b-78288ef46b9c
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential harvesting tool for Windows that extracts browser-stored secrets (passwords, cookies, OAuth refresh tokens, credit cards, autofill, history) from Chrome, Edge, Brave, Opera/Opera GX, Vivaldi, and Firefox; it bypasses Chrome App‑Bound Encryption by injecting a DLL into a headless Chromium process (Early Bird APC) to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parsing). The report covers usage, extracted data, attack scenarios, detection and mitigation guidance, and positions the tool as valuable for red teams while noting its clear misuse potential by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
