Microsoft Patches At Least 34 Bugs Including Pwn2Own Vulnerability
ID: c648d720-5533-5a3f-a83f-1fb35dbea404
STIX ID: report--c648d720-5533-5a3f-a83f-1fb35dbea404
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill, history) from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt the app_bound_encrypted_key, includes DPAPI/NSS handling for other browsers, and contains evasion features (string obfuscation, API hashing, PPID/argument spoofing, custom SQLite parsing); the README documents usage, an attack scenario, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
