logo

WarmCookie Gives Cyberattackers Tasty New Backdoor for Initial Access

ID: 0725006f-1981-5b64-87cf-8a6d1beb4e3b

STIX ID: report--0725006f-1981-5b64-87cf-8a6d1beb4e3b

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-11

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Elastic Security Labs describes WarmCookie, a two-stage Windows backdoor being distributed widely by the REF6127 recruitment-themed phishing campaign; the attack chain uses obfuscated JavaScript and PowerShell (including a CAPTCHA-based landing page), BITS to download a DLL, and a scheduled task named RtlUpd for persistence, while the backdoor performs reconnaissance and can stage ransomware. Researchers note active daily distribution, code overlap with older samples, multiple anti-analysis and obfuscation techniques, and provide YARA rules and behavior-based detections for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.