HTTPBrowser, also known as HTTPDump and Token Control, is a Windows remote-access trojan used in cyberespionage operations by China-linked threat groups, including Wekby (APT18) and BRONZE UNION (APT27). Its capabilities include capturing keystrokes and spawning a reverse shell for remote command execution. Wekby campaigns using HTTPBrowser have targeted manufacturing, technology, and utilities organizations.
HTTPBrowser establishes persistence through user-level Windows Registry autostart entries. Its installation chain can abuse DLL search order and side-loading to execute a malicious library through a legitimate Symantec antivirus executable. The library masquerades as a legitimate Symantec component and decrypts and executes the RAT. HTTPBrowser deletes its original installer after installation, reducing residual artifacts.
Distribution has included IT-helpdesk-themed phishing emails with links or attachments presented as VPN or Citrix upgrades. Typical HTTPBrowser variants communicate over HTTP, while variants deployed by Wekby use DNS TXT records as a covert command-and-control channel. Some variants employ return-oriented programming and elaborate no-operation-like routines to obstruct analysis. Pisloader is an HTTPBrowser variant that also uses DNS-based command-and-control communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT, a tool which is believed to have Chinese origins and to be used only by certain Chinese hacking groups."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan listed in APT27's malware/tool arsenal.
HttpBrowser is mentioned as a malware/tool with capabilities resembling TokyoX, but the article states the sample does not share code or command style with it and is likely a different first-stage tool.
Remote access trojan whose installer uses a malicious DLL named after a legitimate Symantec component.
Backdoor malware that deletes its installer after installation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.