OpenVPN Vulnerable To Shellshock Exploit
ID: 7bccb7d7-d090-5aba-bf08-0f45c3fab386
STIX ID: report--7bccb7d7-d090-5aba-bf08-0f45c3fab386
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation credential-harvesting tool that targets Chrome, Edge, Brave (App-Bound Encryption bypass via IElevator), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It spawns headless Chromium processes and injects a DLL using Early Bird APC injection to decrypt app_bound_encrypted_key values, parses on-disk SQLite/JSON stores, and writes structured JSON output of cookies, saved logins, OAuth tokens, credit cards, autofill data, history, and bookmarks; the tool includes multiple evasion features and is intended for red-team/assumed-breach testing while also posing a real risk if abused by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
