logo

New Research Shows Facebook’s URL Scanner Is Vulnerable To Cloaking

ID: d9a6f4d4-1f5e-5212-af93-6254e5fcab4a

STIX ID: report--d9a6f4d4-1f5e-5212-af93-6254e5fcab4a

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-10-10

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). It uses a headless Chromium process with Early Bird APC DLL injection to call the IElevator COM interface and decrypt app_bound_encrypted_key, includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and is intended for red-team assumed-breach testing but represents a realistic offensive capability for cloud account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.