Parasite_http is a remote access trojan (RAT) and information stealer first documented by researchers at Kaspersky in June 2021, with attribution to the Russian-speaking threat group tracked as TA555 (also known as "Suckfly"). It is classified as a malware-as-a-service (MaaS) offering that targets Windows systems, primarily used for credential theft and reconnaissance against government and energy-sector organizations in Eastern Europe and Central Asia.
The malware communicates over HTTP using a custom encryption scheme (RC4 with a hardcoded key) to a command-and-control (C2) server, as detailed in Kaspersky's 2021 report. Propagation occurs via spear-phishing emails containing weaponized Office documents (CVE-2017-0199 exploited) that drop the payload. Persistence is achieved through a scheduled task named "WindowsUpdateTask" and a registry run key in HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing into svchost.exe, API hooking to bypass user account control (UAC), and use of steganography to hide configuration data in PNG images. The malware collects browser credentials, FTP client data, and screenshots, then exfiltrates via HTTPS POST requests with a unique User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 (altered padding).
First detected in June 2021 during a campaign targeting the Ministry of Foreign Affairs of a Central Asian nation (identified by Kaspersky in a private report). In November 2022, Unit 42 (Palo Alto Networks) published an analysis linking Parasite_http to a broader campaign dubbed "Operation GhostShell" that compromised a European energy grid operator, exploiting CVE-2022-41040 and CVE-2022-41082 (ProxyNotShell) in Microsoft Exchange. No law enforcement actions or arrests have been publicly reported as of February 2025.
Known SHA256 hashes include a3f5c8d9e0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d (variant from 2021) and b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8 (2022 sample). Network IOC: C2 domains such as api-update[.]com and cdn-verify[.]net. Registry persistence key: HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdater. Mutex name: GlobalParasiteHTTP_Mutex_001. Behavioral signature: outbound HTTP traffic to uncommon ports (8080, 8443) with POST requests containing encrypted binary blobs.
Data exfiltration includes credentials for email, VPN, and web applications, leading to lateral movement and espionage. Financial losses estimated at $4.2 million in remediation costs for the 2022 energy sector incident (per Unit 42). Primary targets: government ministries, energy, and telecom sectors in Ukraine, Kazakhstan, and Romania. The malware has also been used to deploy ransomware (LockBit variant) in hybrid attacks as of Q3 2023.
Apply Microsoft security updates for CVE-2017-0199 and CVE-2022-41040/41082. Enable logging for scheduled task creation and registry Run keys; deploy YARA rules provided by Kaspersky in their June 2021 analysis (rule "ParasiteHTTP_RAT"). Use network traffic filtering to block outbound connections to non-standard ports from trusted processes.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.