Clever Attack Allows Theft Of Names & Addresses From IE & Safari
ID: d70f0e51-b940-5bf1-8186-c1ed5fcaa6f2
STIX ID: report--d70f0e51-b940-5bf1-8186-c1ed5fcaa6f2
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium-based browsers by injecting a DLL into a headless Chromium process to call the IElevator COM interface, retrieves DPAPI or NSS keys where applicable, and parses browser SQLite/JSON stores to output extracted secrets as JSON; the report covers its features, evasion techniques, usage examples, detection signals, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
