Microsoft Breaks Patch Cycle to Issue IE Patch
ID: ec56aaaf-1915-52bb-9f0b-a533f0a00291
STIX ID: report--ec56aaaf-1915-52bb-9f0b-a533f0a00291
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool for extracting browser-stored credentials and session data (passwords, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by injecting a DLL into a headless Chromium process via Early Bird APC to leverage the IElevator COM interface, handles DPAPI-protected browsers and NSS-based Firefox logins, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report covers usage, attack scenarios (rapid credential extraction enabling cloud account takeover and lateral movement), detection opportunities, and mitigations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
