HackBrowserData is an open-source, cross-platform browser-data extraction utility widely abused for information theft. It runs on Windows, macOS, and Linux and decrypts and exports saved passwords, cookies, browsing history, bookmarks, and download records from multiple browsers, including Chromium-based browsers and Firefox. It accesses predefined browser storage locations and processes locally stored profile data. Its credential and cookie collection enables password theft and theft of browser session material.
Threat actors deploy both the original utility and modified builds during post-compromise collection. In Operation FlightNight, an uncategorized actor used a modified version against Indian government entities and private energy companies beginning in March 2024. Phishing emails impersonating an Indian Air Force invitation delivered an ISO containing a deceptive shortcut with a PDF icon. Execution displayed a decoy document while the stealer collected data. This variant added document theft, encoded strings decoded at runtime, and exfiltration through attacker-controlled Slack workspaces, targeting browser data alongside office documents, PDFs, and SQL database files.
HackBrowserData has also been used by Hydrochasma in intrusions affecting Asian shipping companies and medical laboratories, by UNC3569 in post-compromise collection, and within MuddyWater's tooling. A modified macOS build has been deployed by XCSSET to collect Firefox data, with the surrounding malware uploading exported archives. Shai-Hulud supply-chain payloads have likewise deployed the utility for browser-data collection. These integrations demonstrate its use as a reusable collection component; persistence, propagation, remote execution, and destructive behavior implemented by the surrounding malware are not intrinsic HackBrowserData capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HackBrowserData: An open-source tool that can decrypt browser data.
The download server contained HackBrowserData, an open-source tool designed for information theft, which includes stealing credentials, history, and cookies stored in web browsers.
The actor also used a powerful command-line tool, HackBrowserData, for decrypting and exporting browser data – it supports the most popular browsers on the market and can be run on Windows, macOS and Linux.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor attempted to dump the “HKLM\SYSTEM” registry by performing command execution.
The open-source post exploitation tool HackBrowserData has the capability to steal browser login credentials, cookies, and history.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named browser-data extraction tool explicitly deployed by the Shai-Hulud payload to decrypt and harvest browser profiles. The report connects its use to cryptocurrency wallet extension data and messaging app databases.
A data-extraction tool explicitly deployed by the Shai-Hulud payload in the compromised tensorlake package as part of its credential-stealing operation. The article does not separately detail the binary's execution or collected artifacts.
A browser-data extraction tool explicitly deployed as part of the Shai-Hulud infection to steal cookies and credentials from browser stores on compromised hosts.
An information-stealing tool used to extract browser credentials, history, and cookies from Chromium-based browsers, Firefox, and Safari.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.