DJI Firmware Hacking Removes Drone Flight Restrictions
ID: 84ad7b92-898f-5597-9089-b43741fe6405
STIX ID: report--84ad7b92-898f-5597-9089-b43741fe6405
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool that harvests credentials and session data from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). The tool spawns a headless Chromium process, injects a DLL using Early Bird APC to access the IElevator COM interface and decrypt the app_bound_encrypted_key, then parses and decrypts on‑disk SQLite/JSON stores to export passwords, cookies, OAuth tokens, credit cards and browsing history as structured JSON; it includes multiple evasion techniques and is intended for red‑team/assumed‑breach testing but represents a realistic offensive capability for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
