Severe Security Hole in Apple Mac Safari Web Browser
ID: d7651f44-3800-5a53-b7b4-9c213bd787fa
STIX ID: report--d7651f44-3800-5a53-b7b4-9c213bd787fa
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation credential‑harvesting tool for Windows that targets Chromium‑based and Gecko‑based browsers to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, uses DPAPI/NSS techniques for other browsers, includes multiple evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), writes structured JSON output, and is positioned as a red‑team tool for assessing the risk of browser‑stored secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
