logo

XcodeGhost iOS Trojan Infected Over 4000 Apps

ID: ebb24525-68cb-5767-9122-bd890118702c

STIX ID: report--ebb24525-68cb-5767-9122-bd890118702c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-09-24

Date Updated: 2026-05-12

...
...

### Executive Summary DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox by bypassing App-Bound Encryption (via DLL injection into a headless Chromium process and the IElevator COM interface), DPAPI, or Firefox NSS; the report details implementation, usage examples, evasion techniques, attack scenarios, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.