Researcher Releases Android Exploit In Webkit Browser Engine
ID: af81dac3-554e-5e31-8591-69af935702db
STIX ID: report--af81dac3-554e-5e31-8591-69af935702db
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major browsers including Chrome/Edge/Brave (App-Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI) and Firefox (NSS). It uses headless Chromium + Early Bird APC DLL injection to access the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is presented as a red-team tool but represents a high-risk capability for real-world adversaries seeking lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
