HTTPSnoop

Aliases: TOFULOAD

First seen
2022-05-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 13:07:40

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the infected endpoint.

Reports & references

  • Cisco Talos — Introducing Shrouded Snooper (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Httpsnoop (report)

External references