OnionC2 – Tor Powered Rust Command and Control Framework
ID: 2caf643b-25b6-5e2a-8694-df49dd34be9e
STIX ID: report--2caf643b-25b6-5e2a-8694-df49dd34be9e
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC) to leverage the IElevator COM interface and decrypt App-Bound Encryption keys, handles DPAPI and NSS decryption for other browsers, includes operational evasion features, and outputs structured JSON for red-team/assumed-breach testing while the report also outlines detection and mitigation approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
