logo

WARMCOOKIE One Year Later: New Features and Fresh Insights

ID: b9094cfb-df31-57f0-bf9b-4b6f47e47387

STIX ID: report--b9094cfb-df31-57f0-bf9b-4b6f47e47387

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2025-10-01

Date Updated: 2026-04-27

...
...

Elastic Security Labs reports continued active development and deployment of the WARMCOOKIE backdoor: new execution handlers (PE, DLL, PowerShell), a campaign ID field for tracking targeting, a dynamic string bank for evasion, and a default SSL certificate useful for tracking C2 infrastructure; the analysis includes numerous C2 IPs/domains and SHA-256 file hashes observed in ongoing malvertising and spam-driven campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.