Four Year Old libssh Bug Leaves Servers Wide Open
ID: 506ce70e-8258-5baa-bb9d-298f1f9d8ae2
STIX ID: report--506ce70e-8258-5baa-bb9d-298f1f9d8ae2
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption on Chrome 127+ by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and implements evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication) to reduce EDR detection; output is structured JSON intended for red‑team use but represents a realistic credential‑harvesting threat to enterprise developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
