Critical Remote Root Zero-Day In FireEye Appliances
ID: a7cb2081-beb9-5fde-a9ab-e8d94eef2208
STIX ID: report--a7cb2081-beb9-5fde-a9ab-e8d94eef2208
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chromium-based browsers (via an App‑Bound Encryption bypass using headless Chromium + DLL injection and the IElevator COM interface), DPAPI-based browsers, and Firefox (NSS decryption). The README documents its operation, evasion features, supported browsers, usage examples, detection opportunities, and red-team relevance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
