Quasar RAT – Windows Remote Administration Tool
ID: cc3216c8-65b9-5d4c-85f3-d6a1111f61fe
STIX ID: report--cc3216c8-65b9-5d4c-85f3-d6a1111f61fe
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation tool designed to harvest browser‑stored credentials and session tokens from major browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium process spawning plus Early Bird APC DLL injection and the IElevator COM interface to decrypt app‑bound keys, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is intended for red team/assumed‑breach testing but represents a high‑impact capability for credential theft and cloud session takeover if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
