logo

TJX Employee Fired for Trying to Fix Things

ID: 72ae0d83-f08f-5922-951d-f08f072cfd5e

STIX ID: report--72ae0d83-f08f-5922-951d-f08f072cfd5e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-05-29

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium (via headless process spawn, Early Bird APC DLL injection, and IElevator COM decryption), supports DPAPI and NSS decryption for other browsers, includes multiple EDR‑evasion techniques, and can quickly enable cloud account takeover and lateral movement from a compromised endpoint; detection guidance and mitigations are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.