Dangerous iPhone iOS JailBreak Exploit Goes Public
ID: db84249f-7f21-5ee0-8ac3-049fd837a20e
STIX ID: report--db84249f-7f21-5ee0-8ac3-049fd837a20e
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers on Windows. It bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt encryption keys, supports DPAPI and NSS decryption for other browsers, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and is positioned as a red-team tool useful for assessing the blast radius of compromised developer workstations while highlighting detection and mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
