HTTPBrowser is a Windows remote access trojan associated with Chinese espionage activity, particularly clusters tracked as APT18 and APT27/BRONZE UNION. It has been used in long-running intrusion operations against sectors including manufacturing, technology, utilities, healthcare, government, defense, and other strategically significant organizations.
The malware provides interactive post-compromise access and supports command-and-control over HTTP and HTTPS. Reported capabilities include keylogging, reverse shell access, persistence, and anti-forensic cleanup. HTTPBrowser has been observed capturing keystrokes, spawning a reverse shell on infected hosts, deleting its original installer after installation, and maintaining persistence through Windows Registry Run entries.
A notable tradecraft pattern is its use of DLL side-loading and DLL search-order abuse to evade detection. In documented deployments, attackers paired a legitimate signed executable with a malicious DLL masquerading as a legitimate vendor library in order to decrypt and launch the RAT. This technique has been linked to broader operational practices of BRONZE UNION and related Chinese intrusion sets.
HTTPBrowser has also appeared in phishing-led campaigns. In one documented operation attributed to Wekby/APT18, obfuscated variants themed as enterprise remote-access or software-upgrade lures were delivered to targets and installed on Windows systems for persistence and remote control. That campaign referred to the malware internally as Token Control and used a covert DNS-based communications variant rather than the more typical HTTP-based traffic, indicating that operators have fielded modified builds adapted for stealth.
Although HTTPBrowser is sometimes discussed alongside PlugX because of overlapping tradecraft such as DLL side-loading and use by China-linked operators, it is treated as a distinct malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT, a tool which is believed to have Chinese origins and to be used only by certain Chinese hacking groups."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan listed in APT27's malware/tool arsenal.
HttpBrowser is mentioned as a malware/tool with capabilities resembling TokyoX, but the article states the sample does not share code or command style with it and is likely a different first-stage tool.
Remote access trojan whose installer uses a malicious DLL named after a legitimate Symantec component.
Backdoor malware that deletes its installer after installation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.