logo

Microsoft Installs Firefox Add-on Without Asking During Recent Patch Tuesday

ID: b7dfa689-8142-56e0-9ee7-2642df605163

STIX ID: report--b7dfa689-8142-56e0-9ee7-2642df605163

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-06-14

Date Updated: 2026-05-13

...
...

**DumpBrowserSecrets** is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). The analysis describes its injection-based method (Early Bird APC into a headless Chromium process using the IElevator COM interface to decrypt app_bound_encrypted_key), operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), typical attack scenarios (rapid extraction enabling cloud account takeover and lateral movement), and detection/mitigation opportunities for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.