TJX (T.J. Maxx and Marshall’s) Hacker Jailed For 30 Years
ID: 68eca286-0f7f-5ca6-ab0d-7dbb24bad089
STIX ID: report--68eca286-0f7f-5ca6-ab0d-7dbb24bad089
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that harvests browser‑stored credentials and session tokens across major Chromium and Gecko browsers. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL that uses the IElevator COM interface to decrypt keys, handles DPAPI keys for Opera/Vivaldi, and uses NSS decryption for Firefox; extracted data (cookies, OAuth tokens, saved logins, credit cards, history) is exported as structured JSON. The report highlights operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication) and provides detection/mitigation guidance relevant to defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
