Skip to content

HackBrowserData

HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations.

Profile source: Mallory opens in a new tab

HackBrowserData

Family profile

HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations. It is designed to decrypt and export data stored by major browsers, including Chromium-based browsers, Firefox, and Safari, and supports execution on Windows, macOS, and Linux. Its collection scope includes saved credentials, cookies, browsing history, and in some reporting, additional browser-stored artifacts such as credit card data. Because it is publicly available and easily modified, it is frequently repurposed by both criminal and state-linked operators as a lightweight infostealing component rather than a full intrusion platform.

Operationally, HackBrowserData is typically used after initial access to harvest browser-resident secrets and session material from compromised hosts. Its capabilities support theft of saved passwords and browser cookies, enabling both credential theft and session hijacking. It has been observed in intrusion sets involving server compromise, ransomware affiliate activity, and espionage-oriented campaigns. Reported users include PRC-nexus UNC3569 in collection activity following supply-chain or other compromises, Iranian MuddyWater tooling chains where it was deployed alongside loaders and tunneling components, and intrusion activity attributed to Larva-26009 targeting MS-SQL servers. It has also been assessed as the likely basis for renamed or modified binaries used during BlackCat/ALPHV intrusions.

The tool is also incorporated into malware ecosystems as an embedded or downloaded component. Modified variants have been used by macOS malware such as XCSSET to steal Firefox and other browser data, demonstrating that operators adapt the project for platform-specific collection and exfiltration workflows. Defenders commonly encounter it either as a standalone command-line utility or as a recompiled, renamed, or otherwise customized derivative intended to blend into broader post-exploitation activity.

HackBrowserData is best classified as an infostealer focused on browser-resident data. It is not inherently tied to a single delivery vector; observed use is predominantly as a secondary payload or operator tool after compromise rather than as the initial infection mechanism.

Capabilities

  • Credential Theft
  • Exfiltration
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 5, 2026
Last activity
Aug 10, 2026
Feed role
C2 / Distribution
Host form
3 IP / 2 hostnames

Leading locations

  • CN1
  • GB1
  • NL1
  • TH1
  • US1

Leading providers

  • 453 Ladplacout Jorakhaebua1
  • Cloudflare, Inc.1
  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • Omegatech LTD1
  • OOO GETWIFI1

Infrastructure traits

  • Hosting 4
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
Larva-26009

The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.

UNC3569

The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data – it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.

MuddyWater

Credential harvesting through tools like Mimikatz and HackBrowserData...

MITRE ATT&CK

HackBrowserData in ATT&CK

8 distinct techniques

Reporting

Research mentioning HackBrowserData

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.