httd is a Go-based Linux implant associated with APT28, also known as Sednit or Fancy Bear, and linked to the broader Roundish and Operation RoundPress webmail espionage activity. It was recovered from infrastructure and victim data tied to campaigns targeting government and defense-related organizations, including Ukrainian entities. The implant is notable for establishing durable access on Linux systems through multiple persistence mechanisms, including cron-based execution, systemd service installation, and SELinux-related evasion or policy manipulation. Available reporting supports its role as a server-side implant used after compromise rather than as the initial intrusion vector. The surrounding campaign ecosystem focused heavily on Roundcube and other webmail platforms, using cross-site scripting and related techniques to steal credentials, exfiltrate mail and contacts, extract two-factor authentication material, and maintain access through forwarding rules and other post-compromise mechanisms. Within that operational context, httd appears to provide persistent Linux foothold capability for follow-on access and control on compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related APT28 Roundcube tooling — "Operation Roundish" (Hunt.io, 2026-01) ... Implant (httd) SHA-256 e76f54b7b98ba3a08f39392e6886a9cb3e97d57b8a076e6b948968d0be392ed8
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Go-имплант httd - Linux-бинарник с persistence через cron (ежеминутный запуск от root), systemd service и обход SELinux.
A Go-based Linux implant (httd) found in a compromised environment provides persistence via cron, systemd, and SELinux.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based Linux implant/backdoor with persistence via cron and systemd, plus SELinux evasion/bypass behavior.
A Go-based Linux implant that provides persistence through cron, systemd, and SELinux.
A statically-linked, stripped Go ELF backdoor implant providing multi-method persistence (cron job executing /.img, systemd service linux.service from /boot, and SELinux policy manipulation via audit2allow/semodule). Strings indicate additional capabilities including HTTP/2, SSH client, WebSockets, staging/downloader behavior, and host reconnaissance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.