logo

FlyingYeti APT Serves Up Cookbox Malware Using WinRAR

ID: fbf912a5-1872-5aad-8518-b2f00383c376

STIX ID: report--fbf912a5-1872-5aad-8518-b2f00383c376

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-31

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Cloudflare observed a month-long FlyingYeti phishing campaign targeting Ukrainian civilians that used debt-related lures to deliver the PowerShell-based Cookbox malware by exploiting WinRAR CVE-2023-38831; attackers performed detailed reconnaissance on communal payment processes, adapted hosting (GitHub, Pixeldrain, Filemail) after takedowns, employed DDNS-based C2 and persistence, and were partially disrupted by Cloudflare and GitHub actions — the report includes IOCs and mitigation guidance (zero trust, EDR, patching, email defenses).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.