XcodeGhost iOS Trojan Infected Over 4000 Apps
ID: ebb24525-68cb-5767-9122-bd890118702c
STIX ID: report--ebb24525-68cb-5767-9122-bd890118702c
Feed Name: Darknet
### Executive Summary DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi and Firefox by bypassing App-Bound Encryption (via DLL injection into a headless Chromium process and the IElevator COM interface), DPAPI, or Firefox NSS; the report details implementation, usage examples, evasion techniques, attack scenarios, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
