Windows Help Vulnerability Exploited In The Wild
ID: 7c97825d-c518-5b04-80ec-98d7096da929
STIX ID: report--7c97825d-c518-5b04-80ec-98d7096da929
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session tokens across major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It uses headless Chromium spawning and Early Bird APC DLL injection to decrypt app_bound_encrypted_key via the IElevator COM interface, returns decrypted keys to the main executable, and parses browser SQLite/JSON stores to output structured JSON, enabling rapid lateral movement and SaaS account takeover; the report also describes operational evasion, detection opportunities, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
