HiKit is a Windows rootkit and backdoor associated with Chinese espionage activity, including reporting that links it to APT17. It has also appeared in a fileless variant referred to as Hias. HiKit is designed for covert persistence and command and control on compromised systems, particularly Windows servers exposed in perimeter or DMZ roles.
A notable characteristic of HiKit is its kernel-level stealth architecture. It installs a malicious driver and positions itself as a virtual network adapter between the network interface and higher-level protocol drivers, allowing it to inspect inbound traffic inside the network stack and parse command traffic without relying on conventional outbound beaconing. This inbound-oriented command-and-control design helps the malware blend with normal web traffic on servers that already receive connections over common service ports. HiKit has been observed using HTTP for command and control and obfuscating communications with XOR encryption.
HiKit provides typical backdoor functionality for post-compromise operations. Confirmed capabilities include creating a remote shell, executing attacker-supplied commands, uploading files from compromised hosts, and supporting peer connections that can facilitate relaying or pivoting through infected systems. It has also been observed forcing infected hosts to operate as proxies, enabling operators to tunnel traffic through compromised infrastructure and support lateral movement when combined with stolen or previously compromised credentials.
For persistence and execution, HiKit has been observed using DLL sideloading involving a malicious DLL loaded as oci.dll. Reporting on its installer behavior also describes deployment of a kernel driver, supporting driver-installation artifacts, and abuse of certificate trust mechanisms to facilitate driver loading. The malware has additionally been documented attempting to weaken driver-signing enforcement as part of installation.
Observed victim systems were primarily Windows servers running web services, indicating a preference for systems whose normal role makes inbound command traffic less conspicuous. HiKit is best characterized as a stealthy rootkit-backed backdoor used in targeted intrusions for long-term access, covert command execution, internal pivoting, and operational concealment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
"...a fileless version of the well-known ‘HiKit’ malware dubbed ‘Hias’."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
4H RAT has the capability to create a remote shell. AuditCred can open a reverse shell on the system to execute commands. PlugX allows actors to spawn a reverse shell on a victim. QuasarRAT can launch a remote shell to execute commands on the victim’s machine.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Minor Software changes: ... Hikit
Backdoor that uses XOR encryption.
Backdoor/tool listed in MITRE ATT&CK Axiom reporting.
Well-known RAT family; content discusses a fileless variant (Hias) and newly discovered persistence mechanism.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.