logo

Android Malware Giving Phones a Hummer

ID: 329abdcc-fab5-50bb-88de-5aafb1547fef

STIX ID: report--329abdcc-fab5-50bb-88de-5aafb1547fef

Feed Name: Darknet

Threat Score
75/100

Date Published: 2016-07-06

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post‑exploitation credential harvesting tool (publicly released) that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill and history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome’s App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, and uses DPAPI/NSS handling for other browsers; output is structured JSON. The tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) designed to evade EDRs and is positioned as a red team utility but could be repurposed by attackers, with detection opportunities centered on anomalous headless browser instantiation, process injection, IElevator calls, and non‑browser reads of browser SQLite files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.