Phishing Campaign Targets Job Seekers With WARMCOOKIE Backdoor
ID: f5ce3950-a940-5c6d-a118-e4cc4c500fd0
STIX ID: report--f5ce3950-a940-5c6d-a118-e4cc4c500fd0
Feed Name: KnowBe4 Blog
Elastic Security researchers observed a spear-phishing campaign since late April 2024 that impersonates recruiting firms to target job seekers. Victims are directed to personalized landing pages that require a CAPTCHA; completing it triggers a malicious JavaScript download which installs the WARMCOOKIE backdoor. The threat actors use compromised infrastructure and frequent domain rotation to evade detection, and WARMCOOKIE is capable of providing remote access and deploying further malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
