IETF Completes Vulnerability Fix For SSL Renegotiation Bug
ID: bc5d5634-610e-5a38-b54d-747c00d9f9c9
STIX ID: report--bc5d5634-610e-5a38-b54d-747c00d9f9c9
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-extraction tool that targets major Chromium- and Gecko-based browsers to retrieve saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history; it implements an App‑Bound Encryption bypass for Chrome/Edge/Brave via DLL injection into a headless Chromium process using Early Bird APC and the IElevator COM interface, and uses DPAPI or NSS handling for other browsers. The README-style report describes capabilities, operational evasion techniques, usage examples, an attack scenario demonstrating rapid credential exfiltration for lateral movement and cloud account takeover, and recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
