OwlProxy is a Windows HTTP proxy backdoor used in espionage intrusions to bridge internet-accessible systems and internal networks. It has been observed since at least 2019 and was publicly identified in attacks against Taiwanese government entities in 2020. The malware is associated in reporting with activity linked to Chimera and has also been observed in intrusion clusters attributed with moderate confidence to Gelsemium, including operations targeting vulnerable IIS and Microsoft Exchange servers in Asia and other regions.
OwlProxy provides remote command execution and tunneling capabilities through HTTP or HTTPS listener endpoints, allowing operators to execute commands on compromised hosts and proxy traffic into otherwise inaccessible internal environments. Multiple variants expose dedicated paths for command execution and proxying, and newer versions added webshell-like file-management functions including directory listing, file upload, and file download. Some samples operate as IIS-loaded HTTP handlers or IIS backdoors, while others create their own HTTP server functionality.
The malware commonly establishes persistence as a Windows service and has been documented in both 32-bit and 64-bit variants. A related installer component, referred to as OwlInstaller, selects and deploys the appropriate payload for the host architecture and configures service-based persistence. Samples have been observed packed with VMProtect, and some variants use encrypted command-and-control traffic with custom encoding or XOR-based schemes. OwlProxy has also been deployed after exploitation of Microsoft Exchange vulnerabilities and alongside web shells, SessionManager, Cobalt Strike, and other post-exploitation tooling.
Victimology includes government, public-sector, and enterprise environments, especially IIS and Exchange infrastructure used as pivots into internal networks. Its role in intrusions is typically long-term access, covert remote administration, and network tunneling rather than destructive or financially motivated activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
IIS backdoors – ESET observed IIS backdoors installed via web shells used in these compromises on four email servers located in Asia and South America. One of the backdoors is publicly known as Owlproxy.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After analyzing this malware sample we could see that it was a recent version of a tool known as OwlProxy, which has been detected on targets hit by the APT group known as Chimera.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
IIS backdoors – ESET observed IIS backdoors installed via web shells used in these compromises on four email servers located in Asia and South America. One of the backdoors is publicly known as Owlproxy.
they have added a new endpoint to the tool, as follows: https://+:443/exchangetopicservices/ Remote CMD addr https://+:443/exchangetopicservices/pp/ Proxy https://+:443/exchangetopicservices/px/ Webshell
The same C&C server was found in both Gelsevirine and Chrommme, both are using two C&C servers.
The most important characteristic of this malware is that it is an HTTP proxy (T1071.001 Application Layer Protocol: Web Protocols) with backdoor functionality.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom HTTP proxy/backdoor deployed as a service-hosted DLL (e.g., wmipd.dll) that handles inbound HTTP requests on specific URL prefixes and supports command execution and proxying to enable pivoting through the compromised server.
Malware used in the Gelsemium-attributed cluster; described as a unique tool in combination with SessionManager and associated with past Gelsemium activity.
A malicious IIS/Windows service–persisted DLL backdoor that registers HTTP handlers on attacker-chosen URLs to provide encrypted command execution (via cmd.exe) and on-demand proxy/tunneling capabilities (connect/send/recv/disconnect) to reach internal hosts through the compromised server.
Backdoor malware with HTTP proxy functionality used to bridge internet and intranet networks, execute commands on compromised systems, and proxy traffic in and out of victim environments via port 80 endpoints.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.