Skip to content

HackBrowserData

HackBrowserData is an open-source browser data extraction utility widely used as an information-stealing tool in intrusion operations.

Profile source: Mallory opens in a new tab

HackBrowserData

Family profile

HackBrowserData is an open-source browser data extraction utility widely used as an information-stealing tool in intrusion operations. It is designed to decrypt and export data stored by major web browsers, including saved credentials, cookies, browsing history, and in some cases other browser-resident artifacts. The tool supports multiple operating systems, notably Windows, macOS, and Linux, and has been observed in both its original form and modified variants adapted for malicious campaigns.

In threat activity, HackBrowserData has been used for credential theft and session theft by extracting browser passwords and cookies from Chromium-based browsers, Firefox variants, Safari, and other popular browsers. Multiple actors have incorporated it into broader post-compromise workflows for intelligence collection, account access, and follow-on intrusion activity. Observed use includes cyber-espionage targeting Indian government and energy-sector entities, operations against shipping and medical organizations in Asia, supply-chain and contractor-linked activity associated with PRC-nexus intrusion sets, and deployment alongside other offensive tooling in server compromises.

Modified variants have extended the original utility beyond browser-data export. Documented enhancements include obfuscation, selective theft of local documents and databases, and exfiltration through attacker-controlled collaboration platforms. On macOS, a modified build has also been used as a Firefox-focused stealer within XCSSET infections. In some campaigns, the tool was delivered through phishing lures and deceptive disk-image or shortcut-based packaging; in others, it was staged from attacker infrastructure after initial compromise or bundled with broader malware frameworks and loaders.

HackBrowserData is best classified as an infostealer utility. Although legitimate in origin as an open-source tool, its recurring operational use by threat actors makes it relevant to credential-access, session hijacking, and data-theft investigations across enterprise and government environments.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 24, 2026
Last activity
Sep 24, 2026
Feed role
C2 / Distribution
Host form
3 IP / 0 hostnames

Leading locations

  • CN1
  • GB1
  • NL1

Leading providers

  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • Omegatech LTD1
  • OOO GETWIFI1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
hydrochasma

HackBrowserData: An open-source tool that can decrypt browser data.

Larva-26009

The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.

UNC3569

The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data – it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.

MuddyWater

Credential harvesting through tools like Mimikatz and HackBrowserData...

MITRE ATT&CK

HackBrowserData in ATT&CK

16 distinct techniques

Reporting

Research mentioning HackBrowserData

Sep 8
Aikido Dev

Compromised Flutter package on pub.dev contains XCSSET malware

The Flutter package universal_file_viewer version 0.1.5 was published to pub.dev with XCSSET malware embedded in its example-project files. Its Dart library code was clean, so consuming the package as a dependency does not execute the payload; exposure occurs when developers clone the repository and build the example app locally. The infection appears to have originated from the maintainer's already compromised workstation rather than a targeted takeover of the package or its users. The malicious files inject Android Gradle, Xcode, and Git pre-commit hooks that contact command-and-control infrastructure and can spread to other developer projects. XCSSET is a macOS-focused developer supply-chain malware family that has evolved to steal browser data—including Safari and Firefox credentials, cookies, and history—Telegram, notes, clipboard contents, and local files; it can also replace copied cryptocurrency wallet addresses. The package sample uses disguised Dock-based persistence and AES-256-CBC-encrypted data exfiltration, while recent XCSSET variants have added stronger persistence, stealthy AppleScript-based execution, and expanded Xcode-project propagation.

Aug 19
Trendai Security

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups | TrendAI (US)

Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.

Jul 29
Malware News

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - Malware Analysis - Malware Analysis, News and Indicators

A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.

Jul 24
Ahnlab Asec

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.