logo

Active Exploitation Of Unpatched PDF Vulnerability

ID: bebdad75-eec3-5119-bcbc-e63711ff4763

STIX ID: report--bebdad75-eec3-5119-bcbc-e63711ff4763

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-01-08

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI or NSS-protected secrets where applicable, and writes structured JSON output; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication) and is positioned for red-team/assumed-breach use but could be misused by attackers to enable lateral movement and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.