Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

HTTPBrowser

Also known asHttpDumpToken Control

HTTPBrowser is a remote access trojan (RAT) believed to have Chinese origins and reported as used by certain Chinese intrusion groups. It has been associated in the provided content with BRONZE UNION / Emissary Panda / APT27 and with Wekby / APT18 / Dynamite Panda. Reported capabilities include keystroke capture and spawning a reverse shell on victim systems. HTTPBrowser has used HTTP and HTTPS for command-and-control, and at least one Wekby campaign used an obfuscated variant that communicated via DNS TXT records as a covert control channel; in that campaign the actors referred to the malware as "Token Control." Infection and execution methods described in the content include strategic web compromises, phishing lures themed as IT helpdesk VPN/Citrix upgrades, and DLL side-loading / DLL search-order hijacking. One documented installer dropped a malicious DLL named navlu.dll, masquerading as a legitimate Symantec DLL, to decrypt and run the RAT; the malware also deleted its original installer after installation. In the Wekby campaign, installers downloaded from phishing URLs installed the malware as %APPDATA%\wdm.exe and established persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run using a value such as wdm; previous samples reportedly used a Run value for 360v. Typical HTTPBrowser traffic was described as using HTTP with the user-agent string HTTPBrowser/1.0. Observed DNS-based C2 domains in the cited campaign included glb.it-desktop.com, local.it-desktop.com, and hi.getgo2.com. Related phishing URLs included hXXp://it-desktop[.]com/vpn/cisco/vpnclient.exe and hXXp://wangke99[.]tgk[.]delldns[.]com/tools.exe. Referenced sample hashes included d0f79de7bd194c1843e7411c473e4288, e5414c5215c9305feeebbe0dbee43567, and 985eba97e12c3e5bce9221631fb66d68.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Threat Group-3390

BRONZE UNION previously used this technique to enable execution of PlugX and HttpBrowser tools in a way that is challenging for network defenders to detect.

via web archiveweb.archive.org
APT 27

"...either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT, a tool which is believed to have Chinese origins and to be used only by certain Chinese hacking groups."

via ncc group researchnccgroup.com
MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

3 techniques
T1059.003Windows Command ShellEvidence3
TacticExecution

The content repeatedly describes use of cmd.exe, cmd /c, Windows command shell, and xp_cmdshell to execute commands, run payloads, launch binaries, perform reconnaissance, persistence, cleanup, and ransomware actions. Examples include: 'Sandworm Team used the xp_cmdshell command in MS-SQL', 'APT41 used cmd.exe /c to execute commands on remote machines', and many malware families 'can use cmd.exe to execute commands on a compromised host.' | Many entries explicitly state malware 'can create a reverse shell' or 'launch a remote shell,' including 4H RAT, AuditCred, BLACKCOFFEE, Carbanak, DarkComet, Exaramel for Windows, PlugX, QuasarRAT, and ZxShell.

T1106Native APIEvidence1
TacticExecution

“find the addresses of LoadLibrary and GetProcAddress to load all the necessary functions dynamically.”

T1574.001DLLEvidence2

“In order to execute the payload, the attackers take advantage of a technique called DLL Search Order Hijacking. Once the malicious DLL is loaded…”

Persistence

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence4

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.

T1547.001Registry Run Keys / Startup FolderEvidence4

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence6
TacticStealth

The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.

T1036MasqueradingEvidence2
TacticStealth

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1036.005Match Legitimate Resource Name or LocationEvidence2
TacticStealth

Akira has used legitimate names and locations for files to evade defenses.

T1070.004File DeletionEvidence7
TacticStealth

The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.

T1574.001DLLEvidence2

“In order to execute the payload, the attackers take advantage of a technique called DLL Search Order Hijacking. Once the malicious DLL is loaded…”

T1056.001KeyloggingEvidence1

Discovery

1 technique
T1083File and Directory DiscoveryEvidence3
TacticDiscovery

“3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory… admin@338 actors used… dir c:\ >> %temp%\download … APT28 has used Forfiles to locate PDF, Excel, and Word documents…”

Collection

1 technique
T1056.001KeyloggingEvidence1
T1071.001Web ProtocolsEvidence5

The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.

T1071.004DNSEvidence1
T1105Ingress Tool TransferEvidence1
T1219Remote Access ToolsEvidence1

4H RAT has the capability to create a remote shell. AuditCred can open a reverse shell on the system to execute commands. PlugX allows actors to spawn a reverse shell on a victim. QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app5 years ago
ACTIVITY FEED

Recent activity

11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.