Microsoft Implements Company Policy For Vulnerability Disclosure
ID: a72626a2-5a83-5164-b337-0d9238fb68d5
STIX ID: report--a72626a2-5a83-5164-b337-0d9238fb68d5
Feed Name: Darknet
DumpBrowserSecrets is a publicly described post-exploitation tool that harvests browser-stored credentials (passwords, cookies, OAuth tokens, credit cards, autofill, history) from major browsers including Chrome, Edge, Brave, Opera family, Vivaldi and Firefox. It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless process and injecting a DLL to use the IElevator COM interface to decrypt keys, includes DPAPI and NSS handling, operational evasion features, and produces structured JSON output to facilitate rapid account takeover and lateral movement; the report also outlines detection and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
