logo

FrSIRT Starts Charging for OTHER Peoples Work (Exploits)

ID: 566020f7-2b71-5ca7-bb73-7afdca6fa114

STIX ID: report--566020f7-2b71-5ca7-bb73-7afdca6fa114

Feed Name: Darknet

Threat Score
80/100

Date Published: 2006-03-19

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from Chrome/Edge/Brave (via an App‑Bound Encryption bypass using DLL injection and the IElevator COM interface), Opera/Vivaldi (DPAPI), and Firefox (NSS), outputting structured JSON and incorporating multiple evasion techniques intended to reduce EDR detection; while framed for red‑team use, it represents a high‑impact credential exposure vector on compromised developer or user endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.