logo

Microsoft Confirms Internet Explorer 0-Day

ID: 6482f497-30eb-57fc-8f89-04036f02417a

STIX ID: report--6482f497-30eb-57fc-8f89-04036f02417a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-04-30

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major Chromium-based browsers and Firefox. The report details a technical App-Bound Encryption bypass for Chrome/Edge/Brave using Early Bird APC DLL injection and the IElevator COM interface, DPAPI handling for Opera-class browsers, NSS decryption for Firefox, operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and an attack scenario showing rapid extraction suitable for lateral movement and SaaS account takeover. Detection and mitigation guidance focuses on monitoring IElevator usage, headless browser instantiation, and non-browser reads of browser SQLite files, while recommending use of external credential managers to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.