Active Exploitation Of Unpatched PDF Vulnerability
ID: bebdad75-eec3-5119-bcbc-e63711ff4763
STIX ID: report--bebdad75-eec3-5119-bcbc-e63711ff4763
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox). It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, retrieves DPAPI or NSS-protected secrets where applicable, and writes structured JSON output; the tool includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication) and is positioned for red-team/assumed-breach use but could be misused by attackers to enable lateral movement and cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
