HTTPSnoop is a Windows backdoor implant associated with the Iranian state-linked ShroudedSnooper group, also tracked as UNC1860, Scarred Manticore, and Storm-0861. It has been deployed on internet-facing servers, including in intrusions targeting Middle Eastern telecommunications providers. The implant interfaces with Windows HTTP kernel drivers to passively monitor inbound HTTP(S) requests matching attacker-defined patterns. Requests disguised as Microsoft Exchange Web Services and Autodiscover traffic can carry encoded shellcode, which HTTPSnoop decodes and executes on the compromised endpoint. This design enables covert remote command execution while blending with expected web-protocol traffic. ShroudedSnooper uses HTTPSnoop alongside web shells and other passive implants to establish and maintain access that may subsequently be used by other Iranian threat groups for espionage, ransomware, or disruptive operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HTTPSnoop is a backdoor implant that interfaces with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute decoded shellcode on the infected internet facing endpoint(s).
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
Tracing other tools used to initiate the BibiWiper attacks against Israel revealed the following overlap in tactics, techniques, and procedures between these attacks and earlier Druidfly attacks: HTTPSnoop malware was previously deployed prior to the Druidfly wiping attacks.
HTTPSnoop malware was previously deployed prior to the Druidfly wiping attacks
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“To masquerade as benign traffic, HTTPSnoop listens to URL patterns that make it look like the infected system being contacted is a server hosting Microsoft’s Exchange Web Services (EWS) API… URLs consisting of ‘ews’ and ‘autodiscover’ keywords over ports 443 and 444.”
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in a pre-destructive indicator chain alongside BibiWiper capability.
Malware used prior to Druidfly wiping attacks, serving as part of the intrusion chain before deployment of destructive payloads.
A passive implant deployed by ShroudedSnooper after gaining initial access, later used to transfer access to other Iranian threat groups.
A Windows HTTP-kernel-level backdoor implant that receives specially patterned HTTP(S) requests, masquerading as Microsoft Exchange Web Services traffic, and decodes and executes supplied shellcode on compromised internet-facing servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.