logo

Phishing Campaign Targets Job Seekers With WARMCOOKIE Backdoor

ID: f5ce3950-a940-5c6d-a118-e4cc4c500fd0

STIX ID: report--f5ce3950-a940-5c6d-a118-e4cc4c500fd0

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-06-14

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Elastic Security researchers observed a spear-phishing campaign since late April 2024 that impersonates recruiting firms to target job seekers. Victims are directed to personalized landing pages that require a CAPTCHA; completing it triggers a malicious JavaScript download which installs the WARMCOOKIE backdoor. The threat actors use compromised infrastructure and frequent domain rotation to evade detection, and WARMCOOKIE is capable of providing remote access and deploying further malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.