Local r00t Exploit ( BID 18874 / CVE-2006-2451 )
ID: fc9878c5-7bed-5e19-b460-601ffc74daaf
STIX ID: report--fc9878c5-7bed-5e19-b460-601ffc74daaf
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption (Chrome 127+) by spawning a headless Chromium process, injecting a DLL via Early Bird APC, and calling the IElevator COM interface to decrypt encryption keys, then parses and decrypts on-disk browser databases to output saved passwords, cookies, OAuth refresh tokens, credit cards and history as JSON. The tool includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) and is intended for red-team assumed-breach assessments but represents a high-risk capability if used by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
