Chinese Firm Writes First SMS Worm
ID: 55fb0261-a99c-543f-9524-bd3385782eee
STIX ID: report--55fb0261-a99c-543f-9524-bd3385782eee
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, and bookmarks) from Chromium-based browsers (including Chrome, Edge, Brave) and Firefox by bypassing App-Bound Encryption or using DPAPI/NSS decryption; it uses headless Chromium + DLL injection (Early Bird APC) to call the IElevator COM interface for key decryption, includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red-team tool for assumed-breach testing while also representing a high-risk infostealer capability if used by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
