WinHTTP - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 22, 2026
Last Seen
August 26, 2026

WinHTTP is Windows HTTP Services that provides HTTP/HTTPS client functionality for applications.

Overview

WinHTTP is Windows HTTP Services that provides HTTP/HTTPS client functionality for applications. In threat activity, malware and backdoors often leverage WinHTTP to perform command-and-control, download modules, and exfiltrate data, using legitimate Windows networking APIs to blend into normal traffic. The LOTUSLITE backdoor reportedly uses WinHTTP for its C2 communications while targeting US policy bodies with lure-based campaigns, illustrating a practical use of this Windows-provided HTTP service in intrusions.

Related Threat Clusters

  • Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool

    The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…

    6 articles · Updated August 26, 2026
  • LOTUSLITE Malware Targets US Government Organizations

    Acronis researchers have identified a malware campaign named LOTUSLITE that targets US government-related organizations using politically themed emails with ZIP attachments to install a backdoor for ongoing access. This…

    1 article · Updated January 22, 2026

Recent Intelligence Reports

  • Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group — Group-Ib · August 26, 2026
  • LOTUSLITE backdoor targets US policy bodies with lures — Itbrief.Au · January 22, 2026

CVSS v3.1 Breakdown