A new version of COMpfun remote access trojan (RAT) has been discovered in the wild that uses HTTP status codes to control compromised systems. The cyberespionage malware was created by the Turla APT, a Russian-based threat group. The initial dropper, upon download, runs the next stage of malware, which communicates with the command-and-control (C2) server using an HTTP status-based module. To hide data locally, the Trojan implements LZNT1 compression and one-byte XOR encryption.
Source: https://thehackernews.com/2020/05/malware-http-codes.html

