logo

Windows Help Vulnerability Exploited In The Wild

ID: 7c97825d-c518-5b04-80ec-98d7096da929

STIX ID: report--7c97825d-c518-5b04-80ec-98d7096da929

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-06-18

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session tokens across major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It uses headless Chromium spawning and Early Bird APC DLL injection to decrypt app_bound_encrypted_key via the IElevator COM interface, returns decrypted keys to the main executable, and parses browser SQLite/JSON stores to output structured JSON, enabling rapid lateral movement and SaaS account takeover; the report also describes operational evasion, detection opportunities, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.