Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 4 hostnames
HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations.
Profile source: Mallory opens in a new tabHackBrowserData
HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations. It is designed to decrypt and export data stored by major browsers, including Chromium-based browsers, Firefox, and Safari, and supports execution on Windows, macOS, and Linux. Its collection scope includes saved credentials, cookies, browsing history, and in some reporting, additional browser-stored artifacts such as credit card data. Because it is publicly available and easily modified, it is frequently repurposed by both criminal and state-linked operators as a lightweight infostealing component rather than a full intrusion platform.
Operationally, HackBrowserData is typically used after initial access to harvest browser-resident secrets and session material from compromised hosts. Its capabilities support theft of saved passwords and browser cookies, enabling both credential theft and session hijacking. It has been observed in intrusion sets involving server compromise, ransomware affiliate activity, and espionage-oriented campaigns. Reported users include PRC-nexus UNC3569 in collection activity following supply-chain or other compromises, Iranian MuddyWater tooling chains where it was deployed alongside loaders and tunneling components, and intrusion activity attributed to Larva-26009 targeting MS-SQL servers. It has also been assessed as the likely basis for renamed or modified binaries used during BlackCat/ALPHV intrusions.
The tool is also incorporated into malware ecosystems as an embedded or downloaded component. Modified variants have been used by macOS malware such as XCSSET to steal Firefox and other browser data, demonstrating that operators adapt the project for platform-specific collection and exfiltration workflows. Defenders commonly encounter it either as a standalone command-line utility or as a recompiled, renamed, or otherwise customized derivative intended to blend into broader post-exploitation activity.
HackBrowserData is best classified as an infostealer focused on browser-resident data. It is not inherently tied to a single delivery vector; observed use is predominantly as a secondary payload or operator tool after compromise rather than as the initial infection mechanism.
C2 tracking
Derp observations, rolling seven-day window
Samples
50aabb2f45a4b755a55d8bfd33a1b2d878fa67c795d081a55e721c922504c670 5279c8c75d464fb0554e8382233d0b964a9f75c7fce8aff965d83e0e2bfb8f9b 59e0967852ffd9900cf5816d3d37f4c1151c64b5d775d801243cf778ecb42696 68ee5cbb84faf7f0368c0683eaa376f18459aa6789dddd955965045251091143 fc850941be7a2e75cabbf7151688a702c9dcd0aa880fe1dfed078eafc2215d8a 2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4fe508025770c53e0717b524175f079ee23443a4ed909a36be04ee7522e7e055 9bb943340f1b6bf6cff15334ab9b0ab32740455f50f76a779f1735445cb521ae ed7b43af39b111ebcfd376a6cd5690bfe6523f053c5e96c136fb8df887f8f21c Reported operators
The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.
The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data β it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.
Credential harvesting through tools like Mimikatz and HackBrowserData...
MITRE ATT&CK
Reporting
A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.