logo

AT&T Hack Exposes 19,000 Identities

ID: e5bd6530-477b-5321-bd5d-5edcf906c0a4

STIX ID: report--e5bd6530-477b-5321-bd5d-5edcf906c0a4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-08-30

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly documented Windows post‑exploitation tool that extracts credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses App‑Bound Encryption on Chromium browsers by spawning a headless browser process and injecting a DLL to call the IElevator COM interface, supports DPAPI and NSS decryption flows, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The tool outputs structured JSON of recovered secrets and is intended for red‑team assumed‑breach testing but presents a high-risk capability if used by adversaries for cloud account takeover, lateral movement, or persistent access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.