Android Malware App Covertly Makes Purchases On China Mobile Market
ID: fa92633a-e273-5998-9137-b609e61b21ca
STIX ID: report--fa92633a-e273-5998-9137-b609e61b21ca
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill entries, history, and bookmarks) from Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, retrieves DPAPI/NSS keys for other browsers, and outputs structured JSON; the report covers its design, evasion features, a red-team attack scenario, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
