WarmCookie Gives Cyberattackers Tasty New Backdoor for Initial Access
ID: 0725006f-1981-5b64-87cf-8a6d1beb4e3b
STIX ID: report--0725006f-1981-5b64-87cf-8a6d1beb4e3b
Feed Name: Dark Reading
Date Published: 2024-06-11
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Elastic Security Labs describes WarmCookie, a two-stage Windows backdoor being distributed widely by the REF6127 recruitment-themed phishing campaign; the attack chain uses obfuscated JavaScript and PowerShell (including a CAPTCHA-based landing page), BITS to download a DLL, and a scheduled task named RtlUpd for persistence, while the backdoor performs reconnaissance and can stage ransomware. Researchers note active daily distribution, code overlap with older samples, multiple anti-analysis and obfuscation techniques, and provide YARA rules and behavior-based detections for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
