Google Removes ‘DroidDream’ Malware From Android Devices
ID: 3bcf5fe0-8763-581d-bf07-e436c91629e1
STIX ID: report--3bcf5fe0-8763-581d-bf07-e436c91629e1
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface to decrypt keys, and it retrieves DPAPI or NSS-protected secrets for other browsers; the report details operational evasion techniques, usage examples, attack scenarios, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
