Dipping into Danger: The WARMCOOKIE backdoor
ID: 8aabb6d3-7b08-525a-bde0-dd84dbcba546
STIX ID: report--8aabb6d3-7b08-525a-bde0-dd84dbcba546
Feed Name: Elastic Security Labs
Elastic Security Labs documents the discovery and analysis of WARMCOOKIE, a newly observed Windows DLL backdoor distributed since April 2024 via recruiting-themed phishing and malicious landing pages (REF6127). The report covers infection chain (obfuscated JS → PowerShell → BITS download → DLL persistence via scheduled task), core capabilities (fingerprinting, screenshots, command execution, file read/write, removal of persistence), network protocol (RC4/Base64 over HTTP cookie parameter to hardcoded C2 IPs), indicators of compromise (domains, IPs, SHA-256), YARA detection rules, and an IDAPython helper for string decryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
