Serious Java Bug Exposes Users To Code Execution
ID: 8d548769-79c4-5c4e-92f3-f33d9f08c7f8
STIX ID: report--8d548769-79c4-5c4e-92f3-f33d9f08c7f8
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool that harvests saved credentials, session cookies, OAuth tokens, credit card data, autofill entries and browsing history from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process and using the IElevator COM interface, handles DPAPI and NSS-encrypted stores, and includes evasion features like string obfuscation, API hashing, PPID/argument spoofing, and custom SQLite parsing; the report also provides attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
