HackBrowserData is an open-source browser data extraction utility widely used as an information-stealing tool in intrusion operations. It is designed to decrypt and export data stored by major web browsers, including saved credentials, cookies, browsing history, and in some cases other browser-resident artifacts. The tool supports multiple operating systems, notably Windows, macOS, and Linux, and has been observed in both its original form and modified variants adapted for malicious campaigns.
In threat activity, HackBrowserData has been used for credential theft and session theft by extracting browser passwords and cookies from Chromium-based browsers, Firefox variants, Safari, and other popular browsers. Multiple actors have incorporated it into broader post-compromise workflows for intelligence collection, account access, and follow-on intrusion activity. Observed use includes cyber-espionage targeting Indian government and energy-sector entities, operations against shipping and medical organizations in Asia, supply-chain and contractor-linked activity associated with PRC-nexus intrusion sets, and deployment alongside other offensive tooling in server compromises.
Modified variants have extended the original utility beyond browser-data export. Documented enhancements include obfuscation, selective theft of local documents and databases, and exfiltration through attacker-controlled collaboration platforms. On macOS, a modified build has also been used as a Firefox-focused stealer within XCSSET infections. In some campaigns, the tool was delivered through phishing lures and deceptive disk-image or shortcut-based packaging; in others, it was staged from attacker infrastructure after initial compromise or bundled with broader malware frameworks and loaders.
HackBrowserData is best classified as an infostealer utility. Although legitimate in origin as an open-source tool, its recurring operational use by threat actors makes it relevant to credential-access, session hijacking, and data-theft investigations across enterprise and government environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HackBrowserData: An open-source tool that can decrypt browser data.
The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.
The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data – it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor attempted to dump the “HKLM\SYSTEM” registry by performing command execution.
The open-source post exploitation tool HackBrowserData has the capability to steal browser login credentials, cookies, and history.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing tool used to extract browser credentials, history, and cookies from Chromium-based browsers, Firefox, and Safari.
An open-source tool used to collect browser data from multiple browsers except Safari.
Open-source browser data extraction tool repurposed/modified and delivered by XCSSET to collect and export Firefox data (e.g., passwords, history, credit cards, cookies) for exfiltration to C2.
A legitimate browser data extraction tool that the report says was distributed from Glutton infrastructure, apparently to steal passwords, cookies, and browsing history from cybercrime operators debugging infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.