Another IE 0-Day Hole Found & Used By In-Memory Drive By Attacks
ID: 464936dc-5ef4-5051-abde-e96de8aa2de0
STIX ID: report--464936dc-5ef4-5051-abde-e96de8aa2de0
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool for Windows that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) across major Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is intended for red team/assumed-breach testing while representing a high-impact credential-theft technique for attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
