logo

Grype – Vulnerability Scanner For Container Images & Filesystems

ID: 53250ac7-2f51-5703-a8e3-1ee46fd2fe20

STIX ID: report--53250ac7-2f51-5703-a8e3-1ee46fd2fe20

Feed Name: Darknet

Threat Score
78/100

Date Published: 2021-04-19

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth tokens, credit cards, autofill and history) from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using a DLL injected into a headless Chromium process and the IElevator COM interface), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The tool outputs structured JSON, includes operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is intended for red-team/assumed-breach scenarios but can enable rapid cloud account takeover and lateral movement on compromised developer endpoints; detection recommendations include monitoring IElevator usage, unexpected headless browser processes, and non-browser reads of browser SQLite databases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.