HTRAN is a Windows-based connection relay and port-forwarding utility used to proxy TCP communications through intermediary systems in order to obscure attacker infrastructure, traverse network boundaries, and expose otherwise unreachable internal services. It is commonly characterized as a malicious communication relay or connection bouncer rather than a full-featured remote access implant. Its core function is to create TCP tunnels and redirect traffic between hosts and ports, enabling operators to hide the true origin of command-and-control activity and to bridge segmented networks during post-compromise operations.
The tool has been used extensively in intrusion operations associated with Chinese espionage activity, including reporting on GALLIUM, APT10, APT12, and Lotus Blossom-related tradecraft, and has appeared in long-running campaigns such as Shady RAT. Operators have used native and modified variants of HTRAN to relay command-and-control traffic, redirect connections between networks, support exfiltration over established channels, and facilitate access to internal services such as Remote Desktop Protocol. Public reporting also describes HTRAN-derived or functionally similar variants, including ONHAT proxy and actor-customized relays.
HTRAN is primarily deployed after initial compromise as post-exploitation infrastructure support. It has been observed installed through compromised web servers and web-shell access, including IIS environments, and used alongside other tooling for persistence, credential theft, lateral movement, and covert remote administration. Some reporting indicates certain HTRAN samples can inject into running processes, which may aid execution and defense evasion. Its operational value lies in proxying and traffic redirection rather than direct collection, but it has been used in campaigns where the relay channel supported both command-and-control and data exfiltration.
HTRAN targets Windows environments and is best understood as a lightweight proxy/backdoor utility used to conceal operator location, tunnel traffic, and maintain covert access paths inside victim networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data.
Regarding the execution, the hostile actor implemented “hTran” backdoor to be able to exfiltrate information.
…released “HTRAN,” a tool designed to obscure an attacker’s location by rerouting internet traffic through intermediary computers… | Other tools developed within former red hacker circles include HTRAN... Designed to obscure an attacker’s location by rerouting internet traffic through intermediary computers, HTRAN has been used in operations such as Shady RAT in 2011 and by Chinese threat groups including GALLIUM and APT12.
...other tools signed with this certificate, such as HTRan, a connection bouncer...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The Comfoo C2 server turns out to be a rendezvous-type traffic relay program... it passes traffic between Comfoo victims and the Comfoo master console operated by the threat actors.
T1090 .001 Internal Proxy Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment.
T1090 .002 External Proxy Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxy malware with functionality similar to ONHAT; referenced as the likely parent/related family of ONHAT.
A traffic relay/proxy tool mentioned as an additional layer of untraceability sometimes used alongside Comfoo infrastructure.
A well-known proxy/port relay tool referenced as the upstream basis for the actor’s modified 'mtrain' relay utility.
HTran is a port-forwarding utility installed after Meterpreter to relay traffic, commonly for remote access such as forwarding RDP connections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.