logo

Quasar RAT – Windows Remote Administration Tool

ID: cc3216c8-65b9-5d4c-85f3-d6a1111f61fe

STIX ID: report--cc3216c8-65b9-5d4c-85f3-d6a1111f61fe

Feed Name: Darknet

Threat Score
75/100

Date Published: 2020-05-27

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly released post‑exploitation tool designed to harvest browser‑stored credentials and session tokens from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium process spawning plus Early Bird APC DLL injection and the IElevator COM interface to decrypt app‑bound keys, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is intended for red team/assumed‑breach testing but represents a high‑impact capability for credential theft and cloud session takeover if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.