Researchers hack Wi-Fi driver to breach laptop
ID: 6307dafe-f97f-55f8-8c45-512fdab5255d
STIX ID: report--6307dafe-f97f-55f8-8c45-512fdab5255d
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers (Chrome/Brave/Edge via an App‑Bound Encryption bypass using the IElevator COM interface; Opera/Opera GX/Vivaldi via DPAPI; Firefox via NSS). It uses headless Chromium spawning, Early Bird APC DLL injection, handle duplication and a custom SQLite parser, includes runtime obfuscation and process-spoofing evasion, outputs structured JSON for red-team use, and presents a significant risk of cloud account takeover and lateral movement if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
