3Com’s TippingPoint Finds New IE Vulnerabilities
ID: 45cfa29c-8099-5183-b46e-40d93fe8972a
STIX ID: report--45cfa29c-8099-5183-b46e-40d93fe8972a
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based and Firefox browsers by using techniques such as headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to bypass App-Bound Encryption; it supports DPAPI and NSS decryption paths, outputs structured JSON, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing), and is positioned for red-team and adversary use to enable rapid lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
