Microsoft IE7 Exploit Allows Remote Code Execution on XP & Vista
ID: 53576c4e-c05e-5261-9374-f0b9cbc3de2d
STIX ID: report--53576c4e-c05e-5261-9374-f0b9cbc3de2d
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data and browsing history from major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It implements an App-Bound Encryption bypass for Chromium (injecting a DLL into a headless Chromium process to call the IElevator COM interface), DPAPI/NSS handling for other browsers, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red-team/assumed-breach use and endpoint control testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
