TJX (T.J. Maxx and Marshall’s) Largest Breach of Customer Data in U.S. History
ID: 5247db63-806a-56c5-9de1-70735c6bce23
STIX ID: report--5247db63-806a-56c5-9de1-70735c6bce23
Feed Name: Darknet
DumpBrowserSecrets is a publicly available Windows post‑exploitation utility that extracts browser‑stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill and history) from major browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (Early Bird APC injection), handles DPAPI and NSS decryption for other browsers, and includes operational evasion features; the report covers usage, attack scenarios, detection opportunities and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
