Android Malware Giving Phones a Hummer
ID: 329abdcc-fab5-50bb-88de-5aafb1547fef
STIX ID: report--329abdcc-fab5-50bb-88de-5aafb1547fef
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential harvesting tool (publicly released) that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill and history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It bypasses Chrome’s App‑Bound Encryption (Chrome 127+) by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface and retrieve decryption keys, and uses DPAPI/NSS handling for other browsers; output is structured JSON. The tool includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser) designed to evade EDRs and is positioned as a red team utility but could be repurposed by attackers, with detection opportunities centered on anomalous headless browser instantiation, process injection, IElevator calls, and non‑browser reads of browser SQLite files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
