logo

Serious Flaw in Popular Media Players from Microsoft and AOL

ID: 419ff816-8ff3-50e8-8882-62a3cfd88ff8

STIX ID: report--419ff816-8ff3-50e8-8882-62a3cfd88ff8

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-12-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave (App‑Bound Encryption bypass via IElevator), Opera/Vivaldi (DPAPI), and Firefox (NSS). It uses DLL injection into a headless Chromium process with Early Bird APC, file-handle duplication to read locked SQLite stores, and multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing) to produce structured JSON output for red-team use and to demonstrate credential exposure risks for cloud and SaaS accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.