Google Chrome 42 Stomps A LOT Of Bugs & Disables Java By Default
ID: 8fa545e5-51ff-50de-a1f0-b4ee7e0d0713
STIX ID: report--8fa545e5-51ff-50de-a1f0-b4ee7e0d0713
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that extracts credentials and session material from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox). It implements an App‑Bound Encryption bypass for Chromium browsers by spawning a headless Chromium process and injecting a DLL (Early Bird APC) to call the IElevator COM interface, retrieves decryption keys (or DPAPI/NSS keys where appropriate), and writes structured JSON output of cookies, saved logins, OAuth tokens, credit cards, autofill and history. The tool includes operational evasion features, supports bulk extraction across installed browsers, and is presented with usage, detection guidance, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
