Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareRansomwareUsed by 2 actors

HackBrowserData

HackBrowserData is an open-source command-line browser data extraction utility used to decrypt and export data stored by popular browsers on Windows, macOS, and Linux. Across the provided reporting, it is consistently described as capable of collecting browser credentials and other browser-resident data, including passwords, cookies, history, credit card data, and related artifacts. Source-code analysis cited in the content indicates it reads predefined browser storage locations and targets fixed credential stores such as Chromium-family Login Data, Network Cookies, and Local State files, as well as Firefox files including cookies.sqlite, key3.db, key4.db, and logins.json.

The tool has been observed or assessed in multiple intrusion contexts. Reporting links its use to PRC-nexus UNC3569 supply-chain and post-compromise activity, where it was used alongside the custom SKYNEEDLE tool to collect browser data, Tencent QQ and WeChat data, system information, and screenshots. It is also described in attacks attributed to Iranian MuddyWater, where the Fooder loader can deploy HackBrowserData as part of a broader espionage toolchain. In BlackCat/ALPHV ransomware intrusions, Cisco Talos assessed that a tool named steal.exe may have been HackBrowserData or a variant. Microsoft also reported a modified HackBrowserData Mach-O FAT binary embedded in a newer XCSSET macOS campaign to steal Firefox data and exfiltrate the resulting archive to command-and-control infrastructure.

The content further places HackBrowserData in the broader ecosystem of credential theft and browser credential dumping under MITRE ATT&CK T1555. It is referenced alongside LaZagne as a commonly used open-source utility for stealing browser credentials, including in attacks against Taiwan critical infrastructure where advanced tools such as LaZagne and HackBrowserData were used to extract NTLM hash passwords. Detection guidance in the content emphasizes that command-line detections are brittle because attackers can modify the binary or rename it, while stronger behavioral detection focuses on unauthorized access to browser credential files. No standalone IOC set specific to HackBrowserData itself is provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC3569

The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data – it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.

via virusbulletinvirusbulletin.com
MuddyWater

Credential harvesting through tools like Mimikatz and HackBrowserData...

via trellix blogtrellix.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

This report focuses on the URLs embedded in emails that bypassed email security controls like secure email gateways (SEGs) to deliver malware.

T1566.002Spearphishing LinkEvidence1

Infection URLs are embedded in emails and represent the first action that a victim must take to become infected.

Credential Access

2 techniques
T1555Credentials from Password StoresEvidence1

The attackers used their custom Golang-based tool, SKYNEEDLE, which is capable of collecting system data, stealing browser information (including Tencent QQ and WeChat data)... The actor also used... HackBrowserData... for decrypting and exporting browser data

T1555.003Credentials from Web BrowsersEvidence3

Browser Credential Dumping - MITRE ATT&CK T1555 Browser Credential dumping is a technique adversaries use to steal credentials from your browsers... Malware such as Redline Stealer, Zaraza bot, and other info stealers have been actively targeting users and organizations to gain access to browser credentials.

Collection

2 techniques
T1074Data StagedEvidence1

Atomic Test #10 - Stage Popular Credential Files for Exfiltration ... search a drive for credential files ... export the found files to a folder

T1560Archive Collected DataEvidence1

Atomic Test #10 - Stage Popular Credential Files for Exfiltration ... export the found files to a folder, and zip it, simulating how an adversary might stage sensitive credential files for exfiltration

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.