Microsoft Installs Firefox Add-on Without Asking During Recent Patch Tuesday
ID: b7dfa689-8142-56e0-9ee7-2642df605163
STIX ID: report--b7dfa689-8142-56e0-9ee7-2642df605163
Feed Name: Darknet
**DumpBrowserSecrets** is a publicly documented post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). The analysis describes its injection-based method (Early Bird APC into a headless Chromium process using the IElevator COM interface to decrypt app_bound_encrypted_key), operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), typical attack scenarios (rapid extraction enabling cloud account takeover and lateral movement), and detection/mitigation opportunities for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
