1200KM / tool
HTRAN — Attack Tool
HTRAN is a tool that proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: HTRAN, HUC Packet Transmit Tool
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT12 · G0005 · Pinned relationship source (relationship--f42a5342-c28d-46ad-bbd7-3123da43ff86)
- GALLIUM · G0093 · Pinned relationship source (relationship--b68c8dc2-e3da-4ce8-aef3-456b160e7fb5)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Command Execution · DC0064
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Firewall Rule Modification · DC0051
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Service Creation · DC0060
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.