logo

PayPal Remote Code Execution Vulnerability Patched

ID: d975cfd7-3d49-51f6-bb80-f8cb1938b7cc

STIX ID: report--d975cfd7-3d49-51f6-bb80-f8cb1938b7cc

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-01-27

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved passwords, cookies, OAuth tokens, credit card numbers, autofill entries and browsing data from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). The report explains the tool's architecture (an executable and a DLL that uses Early Bird APC injection and the IElevator COM interface to bypass App‑Bound Encryption for Chromium builds, plus DPAPI/NSS handling), operational evasion features, typical attack scenarios, recommended detection points and mitigations, and distribution as precompiled binaries on GitHub for red‑team use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.