HTTPSnoop is a passive Windows backdoor associated with Iranian state-linked intrusion activity, particularly the initial-access group ShroudedSnooper, also tracked as UNC1860 and Storm-0861. It is used to establish and maintain covert access on compromised systems by abusing the Windows HTTP stack, fitting a tradecraft pattern centered on low-noise persistence and access handoff to downstream operators.
The malware has been observed alongside other passive implants and webshells, including PipeSnoop, in operations attributed to ShroudedSnooper. This group is assessed to support broader Iranian cyber operations by obtaining footholds and preserving access for later use by other actors conducting espionage, ransomware, or disruptive and destructive activity. HTTPSnoop has also been reported in intrusion chains linked to Druidfly, also known as Homeland Justice and Karma, where its presence preceded BibiWiper-related destructive operations.
Operationally, HTTPSnoop is notable for leveraging native Windows HTTP functionality to blend into legitimate system behavior, which supports stealth and long-term access retention. Its documented role is consistent with a passive implant or backdoor rather than a primary payload for direct monetization or destruction. Reported use cases place it in campaigns targeting organizations of strategic interest in the context of Iranian government-aligned operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
L'attaque est menée à l'aide d'une porte dérobée appelée « HTTPSnoop », qui exploite le noyau HTTP de Windows.
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
ShroudedSnooper is associated with the Iranian government, mainly tasked with gaining initial access and then deploying webshells and passive implants such as HTTPSnoop, PipeSnoop and more.
Tracing other tools used to initiate the BibiWiper attacks against Israel revealed the following overlap in tactics, techniques, and procedures between these attacks and earlier Druidfly attacks: HTTPSnoop malware was previously deployed prior to the Druidfly wiping attacks.
HTTPSnoop malware was previously deployed prior to the Druidfly wiping attacks
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in a pre-destructive indicator chain alongside BibiWiper capability.
Malware used prior to Druidfly wiping attacks, serving as part of the intrusion chain before deployment of destructive payloads.
A passive implant deployed by ShroudedSnooper after gaining initial access, later used to transfer access to other Iranian threat groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.