LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0070: HTTPBrowser

HTTPBrowser is malware that has been used by several threat groups. [1] [2] It is believed to be of Chinese origin. [3]

EnterpriseS0070MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

HTTPBrowser is a Windows malware family in ATT&CK that has been reported as used by multiple threat groups. Its practical significance is not the name of the malware, but the behaviors ATT&CK associates with it: persistence through Run keys or Startup folders, command execution through Windows command shell, credential collection via keylogging, web/DNS-based command-and-control, tool transfer, file discovery, file deletion, obfuscation, and DLL abuse. For leaders, this represents the kind of intrusion tooling that can turn an endpoint compromise into longer dwell time, credential exposure, and harder incident reconstruction.

Executive priority

Prioritize validation around Windows endpoint visibility, identity risk from possible keylogging, and network monitoring for common web and DNS command-and-control patterns. Because ATT&CK provides no official detection text for HTTPBrowser, leadership should not ask whether the organization has a single named-malware alert; they should ask whether SOC and IR teams can prove coverage for the associated behaviors, preserve evidence when files are deleted, and investigate persistence, command execution, and credential-access activity quickly enough to support business continuity and compliance reporting.

Technical view

ATT&CK lists HTTPBrowser as Windows malware and relates it to techniques including T1547.001 Registry Run Keys / Startup Folder, T1059.003 Windows Command Shell, T1056.001 Keylogging, T1071.001 Web Protocols, T1071.004 DNS, T1105 Ingress Tool Transfer, T1083 File and Directory Discovery, T1070.004 File Deletion, T1027 Obfuscated Files or Information, T1036.005 Match Legitimate Resource Name or Location, and T1574.001 DLL. SOC teams should validate behavior-based detections rather than relying on malware naming alone: suspicious autorun changes, unusual cmd.exe activity, anomalous DLL loading or placement, unexpected file enumeration, tool downloads, deletion of staging artifacts, and endpoint processes making unusual HTTP/S or DNS communications.

Likely telemetry

  • Windows endpoint process creation telemetry, especially cmd.exe and parent/child process context
  • Windows Registry and Startup folder change events for persistence validation
  • File creation, modification, deletion, and directory enumeration telemetry
  • DLL load and module path telemetry where available
  • Endpoint security alerts for obfuscated or renamed files and suspicious resource locations

Detection direction

  • Map detections to the related ATT&CK techniques instead of depending on an HTTPBrowser signature or family name.
  • Tune Windows command shell detections for unusual parent processes, rare command patterns, and execution from suspicious locations while accounting for administrator and software-management activity.
  • Validate monitoring for Run key and Startup folder persistence, including user-context autoruns that may be overlooked by server-focused controls.
  • Review DNS and web egress analytics for unusual destinations, rare domains, abnormal beacon-like patterns, or endpoint processes that normally should not initiate external communications.
  • Correlate file deletion with prior tool transfer, command execution, or discovery activity to avoid treating cleanup as benign housekeeping.

Mitigation priorities

  • Strengthen Windows endpoint logging and retention first, because the ATT&CK object does not provide official detection guidance and several related behaviors require host evidence.
  • Harden and monitor autorun locations such as Registry Run keys and Startup folders.
  • Restrict and monitor unnecessary command shell use where operationally feasible.
  • Apply least privilege and credential-protection practices to reduce the value of keylogging and user-context persistence.
  • Control outbound web and DNS traffic through monitored egress paths and investigate endpoints with unusual external communications.
Additional notes and limits

The relationship context is useful for defensive planning: ATT&CK associates HTTPBrowser with APT18 and Threat Group-3390, and with multiple techniques spanning persistence, execution, credential access, discovery, command-and-control, defense evasion, and tool transfer. Glexia would treat this as a behavior-coverage validation exercise for Windows estates, especially where executives need evidence that endpoint, DNS, web, and identity-adjacent telemetry can support incident decisions.

ATT&CK provides no official detection text, no aliases, no explicit tactics on the malware object, and only Windows as the platform for HTTPBrowser. Related technique platform lists include non-Windows platforms, but those should not be interpreted as HTTPBrowser platform support. The supplied data supports historical reporting and ATT&CK relationships, not claims of current active exploitation, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

HTTPBrowser

HTTPBrowser is malware that has been used by several threat groups. [1] [2] It is believed to be of Chinese origin. [3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

11 rows
DomainIDNameRelationship / procedure
EnterpriseT1105Ingress Tool Transfer

HTTPBrowser is capable of writing a file to the compromised system from the C2 server.[2]

EnterpriseT1574.001DLLSub-technique

HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll.[4] HTTPBrowser has also used DLL side-loading.[2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

HTTPBrowser has established persistence by setting the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key value for wdm to the path of the executable. It has also used the Registry entry HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run vpdn “%ALLUSERPROFILE%\%APPDATA%\vpdn\VPDN_LU.exe” to establish persistence.[4][1]

EnterpriseT1027Obfuscated Files or Information

HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

HTTPBrowser is capable of spawning a reverse shell on a victim.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL.[4]

EnterpriseT1071.004DNSSub-technique

HTTPBrowser has used DNS for command and control.[2][1]

EnterpriseT1083File and Directory Discovery

HTTPBrowser is capable of listing files, folders, and drives on a victim.[2][4]

EnterpriseT1056.001KeyloggingSub-technique

HTTPBrowser is capable of capturing keystrokes on victims.[2]

EnterpriseT1071.001Web ProtocolsSub-technique

HTTPBrowser has used HTTP and HTTPS for command and control.[2][1]

EnterpriseT1070.004File DeletionSub-technique

HTTPBrowser deletes its original installer file once installation is complete.[4]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

GroupEnterprise

G0026: APT18

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical. [1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
4e212c6116aef3e0...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle4e212c6116ae…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  2. [2]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  3. [3]
    ThreatConnect Anthem

    ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016.

    Open source URL
  4. [4]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  5. [5]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  6. [6]
    Nccgroup Emissary Panda May 2018

    Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

    Open source URL
  7. [7]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  8. [8]
    RSA2017 Detect and Respond Adair

    Adair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.

    Open source URL
  9. [9]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  10. [10]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  11. [11]
    HttpDump

    (Citation: ThreatConnect Anthem)

  12. [12]
    HttpDump

    (Citation: ThreatConnect Anthem)

  13. [13]
    HttpDump

    (Citation: ThreatConnect Anthem)

  14. [14]
    ThreatConnect Anthem

    ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016.

    Open source URL
  15. [15]
    ThreatConnect Anthem

    ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016.

    Open source URL
  16. [16]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  17. [17]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  18. [18]
    mitre-attackS0070
    Open source URL
  19. [19]
    mitre-attackS0070
    Open source URL
  20. [20]
    mitre-attackS0070
    Open source URL
  21. [21]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  22. [22]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  23. [23]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  24. [24]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  25. [25]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  26. [26]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  27. [27]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  28. [28]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  29. [29]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  30. [30]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  31. [31]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  32. [32]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  33. [33]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  34. [34]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  35. [35]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  36. [36]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  37. [37]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  38. [38]
    Nccgroup Emissary Panda May 2018

    Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

    Open source URL
  39. [39]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  40. [40]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  41. [41]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  42. [42]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  43. [43]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  44. [44]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  45. [45]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  46. [46]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  47. [47]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  48. [48]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  49. [49]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  50. [50]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  51. [51]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  52. [52]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  53. [53]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  54. [54]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  55. [55]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  56. [56]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.