logo

Windows XML Core Services Exploit Attacked In The Wild

ID: ba6d30ac-d7a8-5196-8fa3-e4b25a2c3f76

STIX ID: report--ba6d30ac-d7a8-5196-8fa3-e4b25a2c3f76

Feed Name: Darknet

Threat Score
72/100

Date Published: 2012-06-22

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks) from Chromium‑based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt keys, uses DPAPI extraction where applicable, includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for use in lateral movement or cloud account takeover testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.