Microsoft Warns Of ASP.Net Vulnerability In The Wild
ID: bd92ffcb-15b2-5ccd-8b08-e6a8e59f608a
STIX ID: report--bd92ffcb-15b2-5ccd-8b08-e6a8e59f608a
Feed Name: Darknet
DumpBrowserSecrets is a publicly distributed post‑exploitation tool that extracts browser-stored secrets (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is intended for red team assumed‑breach assessments while also representing a high-risk credential theft capability if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
