Hackers Exploiting Latest Adobe Flash Bug On Large Scale
ID: 60c29703-3e37-5a33-b095-03168ce11083
STIX ID: report--60c29703-3e37-5a33-b095-03168ce11083
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit-card data and other browser-stored secrets from major browsers (Chrome/Edge/Brave, Opera family, Vivaldi, Firefox). It uses a compiled executable and an injected DLL (via Early Bird APC injection) to bypass Chrome's App-Bound Encryption (via the IElevator COM interface), handles DPAPI and NSS models for other browsers, includes multiple operational evasion features, and outputs structured JSON for red-team or attacker use — making it a high-risk tool for account takeover and lateral movement if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
