Proofpoint identified a newly observed modular remote access Trojan, Parasite HTTP, being marketed on underground forums and deployed in a limited email campaign against organizations in the information technology, healthcare, and retail sectors. The attack used resume-themed Microsoft Word attachments containing malicious macros that downloaded the malware, giving operators remote access to infected systems.
The malware stood out for a broad set of anti-analysis and stealth features more commonly associated with higher-end threats, including sandbox detection, anti-debugging, anti-emulation, string obfuscation, hook evasion, and plugin-based modularity. Proofpoint said Parasite HTTP also remapped NTDLL from KnownDlls32 to bypass userland hooks and incorporated publicly available anti-sandbox code, indicating that sophisticated evasion techniques were spreading into commodity malware sold and used more broadly.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
On July 16, 2018, Proofpoint observed a small email campaign delivering Parasite HTTP via resume-themed Microsoft Word attachments with malicious macros. The campaign primarily targeted organizations in the information technology, healthcare, and retail sectors using HR-related distribution lists.
Proofpoint disclosed technical details on Parasite HTTP, including its anti-sandboxing, anti-debugging, string obfuscation, API unhooking, and NTDLL remapping techniques, and shared related indicators such as hashes, delivery URL, command-and-control domains, and an IDS signature.
Proofpoint reported that a newly observed modular Windows remote access Trojan named Parasite HTTP was being advertised for sale on underground markets, with features including plugin support, encrypted communications, persistence, and anti-analysis capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.