Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari
ID: 7d4b0724-32a8-578d-826a-031d904dbe80
STIX ID: report--7d4b0724-32a8-578d-826a-031d904dbe80
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera/Opera GX, Vivaldi, and Firefox) by bypassing App‑Bound Encryption (using IElevator COM from an injected DLL in a headless Chromium process) and handling DPAPI/NSS protections for other browsers; it outputs structured JSON and includes evasion techniques (API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parsing) intended for red-team or adversary use, with guidance on detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
