HTTPHelper is a malware component associated with DPRK-linked cryptocurrency intrusion activity, particularly the fintech-targeting operations tracked as GOLDEN CHOLLIMA. It has been observed as part of a specialized toolkit that includes PipeDown, DevobRAT, and Anycon, with reported shellcode overlaps indicating shared development lineage or code reuse across these families. This tooling cluster is tied to campaigns against cryptocurrency and fintech organizations and reflects the broader evolution of North Korean malware ecosystems derived from earlier shared frameworks.
HTTPHelper is linked to financially motivated operations focused on digital-asset theft rather than broad commodity deployment. Its documented context places it within campaigns targeting cryptocurrency entities, where operators have used trojanized software, malicious development packages, and recruitment-themed social engineering to gain access to victims and support follow-on compromise. The broader actor set associated with this malware has also used cloud-focused post-compromise tradecraft to access identity and infrastructure resources in support of cryptocurrency theft.
Available information supports classifying HTTPHelper as malware used in post-compromise activity within a fintech-focused intrusion toolkit, but the currently available facts do not establish a more precise family role such as loader, RAT, or infostealer with high confidence. Delivery mechanisms specific to HTTPHelper itself are not directly established beyond its association with campaigns using lures and trojanized software. The malware is associated with targeting of cryptocurrency and fintech organizations, especially in economically developed regions, and is part of a coordinated DPRK malware ecosystem characterized by tooling overlap and operational specialization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CrowdStrike Intelligence has observed eight different Jeus and AppleJeus variants in campaigns targeting cryptocurrency entities as well as shellcode overlaps between PipeDown, DevobRAT, HTTPHelper, and Anycon — forming a specialized fintech targeting toolkit.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/tool component in a specialized fintech-targeting toolkit associated with GOLDEN CHOLLIMA through shellcode overlaps.
Referenced as a related malware family showing shellcode overlap with later Jeus/AppleJeus variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.