China Facing Problems With Android Handsets & Pre-installed Trojans
ID: d3faa612-9bdd-5fac-96ab-f45043824d6b
STIX ID: report--d3faa612-9bdd-5fac-96ab-f45043824d6b
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill data, history and bookmarks) from major Chromium-based browsers and Firefox. It includes an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, supports DPAPI and NSS decryption for other browsers, outputs structured JSON, and incorporates evasion features intended to resist EDR detection—making it useful for red teams and attractive to malicious actors seeking cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
