Microsoft Confirms Internet Explorer 0-Day
ID: 6482f497-30eb-57fc-8f89-04036f02417a
STIX ID: report--6482f497-30eb-57fc-8f89-04036f02417a
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks from major Chromium-based browsers and Firefox. The report details a technical App-Bound Encryption bypass for Chrome/Edge/Brave using Early Bird APC DLL injection and the IElevator COM interface, DPAPI handling for Opera-class browsers, NSS decryption for Firefox, operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and an attack scenario showing rapid extraction suitable for lateral movement and SaaS account takeover. Detection and mitigation guidance focuses on monitoring IElevator usage, headless browser instantiation, and non-browser reads of browser SQLite files, while recommending use of external credential managers to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
