logo

Adobe Promises Patch For Flash 0-day Being Used In Targeted Attacks

ID: 394d9fce-1343-52d6-9735-bf3bac55c5e6

STIX ID: report--394d9fce-1343-52d6-9735-bf3bac55c5e6

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-03-15

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly described post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium- and Gecko-based browsers on Windows. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, handles DPAPI and NSS-encrypted stores, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team assumed-breach testing and assessing endpoint detection capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.