Last seven days
- First activity
- Aug 5, 2026
- Last activity
- Aug 10, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 2 hostnames
HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations.
Profile source: Mallory opens in a new tabHackBrowserData
HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations. It is designed to decrypt and export data stored by major browsers, including Chromium-based browsers, Firefox, and Safari, and supports execution on Windows, macOS, and Linux. Its collection scope includes saved credentials, cookies, browsing history, and in some reporting, additional browser-stored artifacts such as credit card data. Because it is publicly available and easily modified, it is frequently repurposed by both criminal and state-linked operators as a lightweight infostealing component rather than a full intrusion platform.
Operationally, HackBrowserData is typically used after initial access to harvest browser-resident secrets and session material from compromised hosts. Its capabilities support theft of saved passwords and browser cookies, enabling both credential theft and session hijacking. It has been observed in intrusion sets involving server compromise, ransomware affiliate activity, and espionage-oriented campaigns. Reported users include PRC-nexus UNC3569 in collection activity following supply-chain or other compromises, Iranian MuddyWater tooling chains where it was deployed alongside loaders and tunneling components, and intrusion activity attributed to Larva-26009 targeting MS-SQL servers. It has also been assessed as the likely basis for renamed or modified binaries used during BlackCat/ALPHV intrusions.
The tool is also incorporated into malware ecosystems as an embedded or downloaded component. Modified variants have been used by macOS malware such as XCSSET to steal Firefox and other browser data, demonstrating that operators adapt the project for platform-specific collection and exfiltration workflows. Defenders commonly encounter it either as a standalone command-line utility or as a recompiled, renamed, or otherwise customized derivative intended to blend into broader post-exploitation activity.
HackBrowserData is best classified as an infostealer focused on browser-resident data. It is not inherently tied to a single delivery vector; observed use is predominantly as a secondary payload or operator tool after compromise rather than as the initial infection mechanism.
C2 tracking
Derp observations, rolling seven-day window
Samples
431640813c3100472ec116fd3b062dab8876a4674091e3fe2bdf22ab3bbc4713 59e0967852ffd9900cf5816d3d37f4c1151c64b5d775d801243cf778ecb42696 5fd493615b731c767be670d33a4e48ec89ad264bf583c2b087d7645a4727986b c9353f6f758a66cdc9eb3deea93ac49d6e1c08a31f3b6d21a96ce2cd8647be6d de8ee2662fda60e9a2983bd84fbb1a2903f5fe1c29923cbfd2190cf46959227b 2b7a30a5236884525a304f128dc18c64dd036640a8f9a7d4076951cb9b7a4b4c 422a9bf06e374480fad6bd0218f46f3599146fcfd420ef9a700e9618d164b5dd 4ace9532c6cadf18cab8a4a612cdee8a6d95b4a90b49a6cbb35db7773a4e7dc5 b6c8d21863a82ed380a9baf46f5e4ec423cb53913f6281bbd258895d4d84f82a ef3692f67a66c0def6557e121cb0f0338e08a29f225d78c081ff9376a41c77c2 Reported operators
The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.
The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data β it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.
Credential harvesting through tools like Mimikatz and HackBrowserData...
MITRE ATT&CK
Reporting
A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.