logo

2 Different Hacker Groups Exploit The Same IE 0-Day

ID: 38b240fe-9c73-5ded-891c-dab0541f065d

STIX ID: report--38b240fe-9c73-5ded-891c-dab0541f065d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-02-02

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera-family browsers, Vivaldi, and Firefox by bypassing App-Bound Encryption (via IElevator COM and Early Bird APC DLL injection) or using DPAPI/NSS decryption. The tool outputs structured JSON, includes multiple operational evasion techniques to reduce detection, and is presented for red-team/assumed-breach use but represents a high-risk capability for cloud account takeover and persistent access if used by attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.