logo

OnionC2 – Tor Powered Rust Command and Control Framework

ID: 2caf643b-25b6-5e2a-8694-df49dd34be9e

STIX ID: report--2caf643b-25b6-5e2a-8694-df49dd34be9e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-06-30

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that targets Chromium-based (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox browsers to extract saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC) to leverage the IElevator COM interface and decrypt App-Bound Encryption keys, handles DPAPI and NSS decryption for other browsers, includes operational evasion features, and outputs structured JSON for red-team/assumed-breach testing while the report also outlines detection and mitigation approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.