New Research Shows Facebook’s URL Scanner Is Vulnerable To Cloaking
ID: d9a6f4d4-1f5e-5212-af93-6254e5fcab4a
STIX ID: report--d9a6f4d4-1f5e-5212-af93-6254e5fcab4a
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). It uses a headless Chromium process with Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and is intended for red-team assumed-breach testing but represents a realistic offensive capability for cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
