logo

Dipping into Danger: The WARMCOOKIE backdoor

ID: 8aabb6d3-7b08-525a-bde0-dd84dbcba546

STIX ID: report--8aabb6d3-7b08-525a-bde0-dd84dbcba546

Feed Name: Elastic Security Labs

Threat Score
72/100

Date Published: 2024-06-12

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents the discovery and analysis of WARMCOOKIE, a newly observed Windows DLL backdoor distributed since April 2024 via recruiting-themed phishing and malicious landing pages (REF6127). The report covers infection chain (obfuscated JS → PowerShell → BITS download → DLL persistence via scheduled task), core capabilities (fingerprinting, screenshots, command execution, file read/write, removal of persistence), network protocol (RC4/Base64 over HTTP cookie parameter to hardcoded C2 IPs), indicators of compromise (domains, IPs, SHA-256), YARA detection rules, and an IDAPython helper for string decryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.