Microsoft Rushes Out Critical RPC Bug Fix
ID: 80fe4229-a717-5e8f-94e3-223509aad695
STIX ID: report--80fe4229-a717-5e8f-94e3-223509aad695
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from major Windows browsers including Chrome/Edge/Brave (using an App-Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It achieves Chromium decryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface to decrypt the app_bound_encrypted_key, then reads and decrypts browser SQLite/JSON stores; it includes multiple EDR-evasion features and writes structured JSON output useful for session replay and lateral access testing. Detection opportunities include anomalous process injection into Chromium, non-browser reads of browser SQLite files, and IElevator COM calls from non-browser contexts; mitigations include moving secrets to dedicated credential managers and EDRs that monitor the described behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
