logo

Microsoft Breaks Patch Cycle to Issue IE Patch

ID: ec56aaaf-1915-52bb-9f0b-a533f0a00291

STIX ID: report--ec56aaaf-1915-52bb-9f0b-a533f0a00291

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-12-17

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a precompiled Windows post-exploitation tool for extracting browser-stored credentials and session data (passwords, cookies, OAuth tokens, credit cards, autofill, history, bookmarks) from Chromium-based browsers and Firefox. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by injecting a DLL into a headless Chromium process via Early Bird APC to leverage the IElevator COM interface, handles DPAPI-protected browsers and NSS-based Firefox logins, and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, and a custom SQLite parser). The report covers usage, attack scenarios (rapid credential extraction enabling cloud account takeover and lateral movement), detection opportunities, and mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.