HackBrowserData is an open-source browser data extraction utility widely used as a credential-access and information-theft tool in post-compromise operations. It is designed to decrypt and export data stored by major browsers, including Chromium-based browsers, Firefox, and Safari, and supports execution on Windows, macOS, and Linux. Its collection scope includes saved credentials, cookies, browsing history, and in some reporting, additional browser-stored artifacts such as credit card data. Because it is publicly available and easily modified, it is frequently repurposed by both criminal and state-linked operators as a lightweight infostealing component rather than a full intrusion platform.
Operationally, HackBrowserData is typically used after initial access to harvest browser-resident secrets and session material from compromised hosts. Its capabilities support theft of saved passwords and browser cookies, enabling both credential theft and session hijacking. It has been observed in intrusion sets involving server compromise, ransomware affiliate activity, and espionage-oriented campaigns. Reported users include PRC-nexus UNC3569 in collection activity following supply-chain or other compromises, Iranian MuddyWater tooling chains where it was deployed alongside loaders and tunneling components, and intrusion activity attributed to Larva-26009 targeting MS-SQL servers. It has also been assessed as the likely basis for renamed or modified binaries used during BlackCat/ALPHV intrusions.
The tool is also incorporated into malware ecosystems as an embedded or downloaded component. Modified variants have been used by macOS malware such as XCSSET to steal Firefox and other browser data, demonstrating that operators adapt the project for platform-specific collection and exfiltration workflows. Defenders commonly encounter it either as a standalone command-line utility or as a recompiled, renamed, or otherwise customized derivative intended to blend into broader post-exploitation activity.
HackBrowserData is best classified as an infostealer focused on browser-resident data. It is not inherently tied to a single delivery vector; observed use is predominantly as a secondary payload or operator tool after compromise rather than as the initial infection mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.
The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data – it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor attempted to dump the “HKLM\SYSTEM” registry by performing command execution.
HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.
Browser Credential Dumping - MITRE ATT&CK T1555 Browser Credential dumping is a technique adversaries use to steal credentials from your browsers... Malware such as Redline Stealer, Zaraza bot, and other info stealers have been actively targeting users and organizations to gain access to browser credentials.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing tool used to extract browser credentials, history, and cookies from Chromium-based browsers, Firefox, and Safari.
An open-source tool used to collect browser data from multiple browsers except Safari.
Open-source browser data extraction tool repurposed/modified and delivered by XCSSET to collect and export Firefox data (e.g., passwords, history, credit cards, cookies) for exfiltration to C2.
An open-source browser credential extraction tool that reads known browser data paths to dump stored credentials, cookies, and related data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.