LiteHTTP is a .NET-based HTTP bot written in C# and associated with commodity botnet operations active by at least 2018. It uses a web-based command-and-control panel with multi-user administration, privilege separation, and action logging, indicating use as a managed botnet platform rather than a single-purpose implant. Documented bot functions include download-and-execute tasking, optional code injection during execution, visible or hidden webpage visits, startup persistence, host profiling, updating, and self-uninstallation. Reported host reconnaissance includes collection of operating system details, version information, and installation location. A basic botkiller capability has also been advertised.
LiteHTTP has been observed in multiple malware sightings and panel deployments, with a notable increase in sample volume during May 2018. Its design and feature set have also been cited as an influence on later malware, including DarkRATv2, which reportedly reused ideas and code from LiteHTTP alongside other publicly available crimeware projects. The malware is best characterized as a Windows bot/backdoor framework operated over HTTP through a centralized panel, suitable for post-compromise tasking and botnet management.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
208 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.