logo

Chinese Firm Writes First SMS Worm

ID: 55fb0261-a99c-543f-9524-bd3385782eee

STIX ID: report--55fb0261-a99c-543f-9524-bd3385782eee

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-07-30

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by bypassing App-Bound Encryption or using DPAPI/NSS decryption; it uses headless Chromium + DLL injection (Early Bird APC) to call the IElevator COM interface for key decryption, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red-team tool for assumed-breach testing while also representing a high-risk infostealer capability if used by malicious actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.