logo

Google Removes ‘DroidDream’ Malware From Android Devices

ID: 3bcf5fe0-8763-581d-bf07-e436c91629e1

STIX ID: report--3bcf5fe0-8763-581d-bf07-e436c91629e1

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-03-07

Date Updated: 2026-05-18

...
...

DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, and it retrieves DPAPI or NSS-protected secrets for other browsers; the report details operational evasion techniques, usage examples, attack scenarios, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.