Adobe Scrambling To Fix Another Serious PDF Flaw
ID: 936479c0-64c3-55c5-a4ce-24423219a699
STIX ID: report--936479c0-64c3-55c5-a4ce-24423219a699
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL that leverages the IElevator COM interface (via Early Bird APC injection) to decrypt the app_bound_encrypted_key; for DPAPI and NSS-based stores it retrieves and decrypts secrets accordingly. The report covers extracted data types, evasion techniques, an operational attack scenario, detection opportunities, and mitigation recommendations for enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
