logo

Android Malware App Covertly Makes Purchases On China Mobile Market

ID: fa92633a-e273-5998-9137-b609e61b21ca

STIX ID: report--fa92633a-e273-5998-9137-b609e61b21ca

Feed Name: Darknet

Threat Score
75/100

Date Published: 2012-07-09

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill entries, history, and bookmarks) from Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI/NSS keys for other browsers, and outputs structured JSON; the report covers its design, evasion features, a red-team attack scenario, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.