logo

MS12-020 RDP Exploit Code In The Wild

ID: 5d2d0d50-29ad-5f67-9cb4-d1b0744d9c5e

STIX ID: report--5d2d0d50-29ad-5f67-9cb4-d1b0744d9c5e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-03-19

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that targets major Windows browsers (Chromium-based and Firefox) to extract saved logins, cookies, OAuth refresh tokens, credit card data, autofill entries and history. It uses a compiled executable and injected DLL to bypass Chrome's App-Bound Encryption (via spawning a headless Chromium process and using the IElevator COM interface with Early Bird APC injection), handles DPAPI and NSS decryption for other browsers, includes evasion techniques to reduce EDR detection, writes structured JSON output, and is intended for red-team/assumed-breach testing but represents a capable threat if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.