logo

Torpig Botnet Hijacking Reveals 70GB Of Stolen Data

ID: e9fe5e54-85f3-514c-b5ea-368deb7e6d7d

STIX ID: report--e9fe5e54-85f3-514c-b5ea-368deb7e6d7d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2009-05-05

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly‑released post‑exploitation tool that harvests browser‑stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from Chrome, Edge, Brave, Opera family, Vivaldi and Firefox on Windows. It bypasses Chrome’s App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI/NSS decryption for other browsers, includes multiple EDR‑evasion techniques, outputs structured JSON, and is intended for red‑team assumed‑breach testing but poses a real risk for credential theft and cloud account takeover if misused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.