Fake browser updates spread updated WarmCookie malware
ID: 74eb5444-27b9-559b-b828-806da08ea858
STIX ID: report--74eb5444-27b9-559b-b828-806da08ea858
Feed Name: Bleeping Computer
A newly observed FakeUpdate campaign targeting users in France leverages compromised websites to present fake browser and Java update prompts that install the WarmCookie Windows backdoor. Discovered by Gen Threat Labs, the campaign delivers an updated WarmCookie with capabilities for device fingerprinting, data and file theft, program enumeration, arbitrary command execution, DLL/EXE/PowerShell transfer and execution, anti-VM checks, and C2 communication; multiple deceptive domains and IoCs were reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
