logo

XRayC2 – Weaponizing AWS X-Ray for Covert Command and Control (C2)

ID: 2113925a-bf8e-5e5c-bee4-41e7a8a20c5c

STIX ID: report--2113925a-bf8e-5e5c-bee4-41e7a8a20c5c

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-10-20

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, browsing history, and bookmarks from Chromium- and Firefox-based browsers on Windows. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt the app_bound_encrypted_key, includes DPAPI and NSS handling for other browsers, and contains operational evasion features; output is structured JSON intended for red-team assumed-breach use but could be repurposed by adversaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.