Researchers reported a surge in LiteHTTP malware activity, identifying 106 samples first seen on VirusTotal during a short period in May 2018 and linking many of them to the same command-and-control infrastructure at topksa[.]net. Observed panel paths included hxxp://topksa[.]net/Panel/page[.]php and hxxp://topksa[.]net/Panel/login/, and the panel was still reachable at the time of reporting. Additional LiteHTTP panels, domains, IP addresses, and malware hashes were also tied to infrastructure active since at least April 2018.
Publicly available source material shows LiteHTTP was presented as an HTTP bot written in C# for .NET 2.0, with a web-based administration panel and features consistent with botnet operations. The advertised capabilities included download-and-execute, persistence, host information collection, webpage visits, updating, and uninstalling, as well as multi-user panel access, privilege controls, and action logging. Together, the reporting and code repository indicate an actively used malware family supported by accessible operator tooling and shared C2 infrastructure.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The GitHub repository for LiteHTTP shows its latest visible commit by zettabithf on October 28, 2018, indicating the malware tooling was maintained through at least that date.
The IOC post states that sightings of new LiteHTTP samples on VirusTotal stopped after May 20, 2018, ending the May spike described by the researcher.
The analysis reports that 106 LiteHTTP malware samples were first seen on VirusTotal between May 2 and May 20, 2018, marking a notable surge in sightings. Many of those samples reportedly communicated with the same topksa.net control panel.
The IOC-focused analysis states that other LiteHTTP command-and-control panels had been active since April 1, 2018. It lists multiple panel URLs, domains, IPs, and associated sample hashes tied to that infrastructure.
A commit message in the LiteHTTP GitHub repository states "Fixed Broken Encryption," indicating a code change to the malware tooling. The repository dates that commit to October 5, 2017.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 166 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.