httpclient

MITRE ATT&CK: S0068 View on attack.mitre.org

Aliases: httpclient

First seen
2014-06-09 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:35:22

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:us country_code:jp

Context

httpclient is malware used by Putter Panda. It is a simple tool that provides a limited range of functionality, suggesting it is likely used as a second-stage or supplementary/backup tool.

Detection coverage

  • 58 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Command Shell (attack-pattern)

Used by threat actors

Reports & references

  • cdn0.vox-cdn.com — Crowdstrike Intelligence Report Putter Panda.Original (report)
  • MITRE ATT&CK — S0068 (report)

External references