New Argument Switch Attack Bypasses Windows Security Software
ID: f5fde0fe-6cbf-5b1b-a4f0-4092bbb8e2c0
STIX ID: report--f5fde0fe-6cbf-5b1b-a4f0-4092bbb8e2c0
Feed Name: Darknet
**DumpBrowserSecrets** is a publicly released post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). It uses headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to obtain encryption keys, outputs structured JSON of recovered secrets, includes multiple evasion techniques, and is intended for red-team assumed‑breach testing but represents a realistic threat vector for cloud/SaaS account takeover and lateral movement if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
