Apple Bans Security Researcher Charlie Miller For Exposing iOS Exploit
ID: 9fc4c46e-c9c6-5f84-8208-e0fa9b0cff00
STIX ID: report--9fc4c46e-c9c6-5f84-8208-e0fa9b0cff00
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox; it implements an App‑Bound Encryption bypass by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, and includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parsing), making it a high-risk capability for lateral movement and cloud account takeover in compromised developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
