HTTPSnoop is a passive implant malware family used by Iranian-linked threat activity to establish and maintain covert access on compromised networks. Cisco Talos reporting cited in the source material states that ShroudedSnooper, also tracked as UNC1860, Scarred Manticore, and Storm-0861, deploys HTTPSnoop alongside webshells and other passive implants such as PipeSnoop after gaining initial access, with the purpose of preserving access for later transfer to other Iranian threat groups. The content associates ShroudedSnooper with the Iranian government and characterizes it as a state-sponsored initial access group.
The malware is also described in relation to Druidfly, also known as Homeland Justice and Karma. The source states that Druidfly maintained BibiWiper capability pre-staged with HTTPSnoop malware, AnyDesk, ScreenConnect, and ReGeorg web shells, making HTTPSnoop part of a recognizable pre-destructive indicator chain. Additional reporting in the content notes that HTTPSnoop had been deployed prior to Druidfly wiping attacks against Israel, indicating its use as a precursor implant before disruptive or destructive operations.
High-confidence associations in the provided content therefore link HTTPSnoop to Iranian government-aligned operations, especially ShroudedSnooper initial access activity and Druidfly pre-wiper intrusion chains targeting Israeli victims. The content does not provide specific technical indicators such as hashes, domains, or file paths for HTTPSnoop.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
Tracing other tools used to initiate the BibiWiper attacks against Israel revealed the following overlap in tactics, techniques, and procedures between these attacks and earlier Druidfly attacks: HTTPSnoop malware was previously deployed prior to the Druidfly wiping attacks.
HTTPSnoop malware was previously deployed prior to the Druidfly wiping attacks
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in a pre-destructive indicator chain alongside BibiWiper capability.
Malware used prior to Druidfly wiping attacks, serving as part of the intrusion chain before deployment of destructive payloads.
A passive implant deployed by ShroudedSnooper after gaining initial access, later used to transfer access to other Iranian threat groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.