Microsoft IIS Semicolon Bug Leaves Servers Vulnerable
ID: cfdfbb6d-2a1a-553c-8620-14ae0683ce94
STIX ID: report--cfdfbb6d-2a1a-553c-8620-14ae0683ce94
Feed Name: Darknet
DumpBrowserSecrets is a publicly distributed Windows post‑exploitation tool that extracts credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to use the IElevator COM interface, retrieves DPAPI and NSS keys for other browsers, and outputs structured JSON of recovered cookies, saved logins, OAuth refresh tokens, credit cards, autofill data and history. The tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication and a custom SQLite parser) and is intended for red team/assumed‑breach testing but represents a high‑impact credential theft capability if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
