Critical 0-day Vulnerability In Adobe Flash Player, Reader & Acrobat
ID: bd667b34-d0b2-5dad-8d64-3e691888d0c9
STIX ID: report--bd667b34-d0b2-5dad-8d64-3e691888d0c9
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-extraction tool that targets major Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox to harvest saved passwords, cookies, OAuth tokens, credit cards, autofill data, and history. It implements a Chrome App-Bound Encryption bypass by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key, handles DPAPI and NSS decryption for other browsers, and includes operational evasion features; output is structured JSON for red-team use and the report includes detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
