WinHTTP is Windows HTTP Services that provides HTTP/HTTPS client functionality for applications.
Overview
WinHTTP is Windows HTTP Services that provides HTTP/HTTPS client functionality for applications. In threat activity, malware and backdoors often leverage WinHTTP to perform command-and-control, download modules, and exfiltrate data, using legitimate Windows networking APIs to blend into normal traffic. The LOTUSLITE backdoor reportedly uses WinHTTP for its C2 communications while targeting US policy bodies with lure-based campaigns, illustrating a practical use of this Windows-provided HTTP service in intrusions.
Related Threat Clusters
-
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
LOTUSLITE Malware Targets US Government Organizations
Acronis researchers have identified a malware campaign named LOTUSLITE that targets US government-related organizations using politically themed emails with ZIP attachments to install a backdoor for ongoing access. This…
1 article · Updated January 22, 2026
Recent Intelligence Reports
- Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group — Group-Ib · August 26, 2026
- LOTUSLITE backdoor targets US policy bodies with lures — Itbrief.Au · January 22, 2026