logo

Microsoft UK Defaced by Saudi Hackers

ID: bcf07f63-723a-55a5-ab9f-bdd3e5876e9e

STIX ID: report--bcf07f63-723a-55a5-ab9f-bdd3e5876e9e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-08-29

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available Windows post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill and history) from Chromium-based and Firefox browsers by using DLL injection into a headless Chromium process to bypass App‑Bound Encryption (via the IElevator COM interface) or by extracting DPAPI/NSS keys; it outputs structured JSON and includes multiple operational evasion features. The report documents usage, extracted data types, an assumed-breach attack scenario, detection opportunities (process injection, IElevator calls, reads of browser SQLite DBs) and mitigation recommendations such as using external credential managers and EDR rules that monitor the described behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.