Grype – Vulnerability Scanner For Container Images & Filesystems
ID: 53250ac7-2f51-5703-a8e3-1ee46fd2fe20
STIX ID: report--53250ac7-2f51-5703-a8e3-1ee46fd2fe20
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth tokens, credit cards, autofill and history) from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using a DLL injected into a headless Chromium process and the IElevator COM interface), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The tool outputs structured JSON, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is intended for red-team/assumed-breach scenarios but can enable rapid cloud account takeover and lateral movement on compromised developer endpoints; detection recommendations include monitoring IElevator usage, unexpected headless browser processes, and non-browser reads of browser SQLite databases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
