Windows XML Core Services Exploit Attacked In The Wild
ID: ba6d30ac-d7a8-5196-8fa3-e4b25a2c3f76
STIX ID: report--ba6d30ac-d7a8-5196-8fa3-e4b25a2c3f76
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks) from Chromium‑based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt keys, uses DPAPI extraction where applicable, includes multiple operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for use in lateral movement or cloud account takeover testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
