logo

Fake browser updates spread updated WarmCookie malware

ID: 74eb5444-27b9-559b-b828-806da08ea858

STIX ID: report--74eb5444-27b9-559b-b828-806da08ea858

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A newly observed FakeUpdate campaign targeting users in France leverages compromised websites to present fake browser and Java update prompts that install the WarmCookie Windows backdoor. Discovered by Gen Threat Labs, the campaign delivers an updated WarmCookie with capabilities for device fingerprinting, data and file theft, program enumeration, arbitrary command execution, DLL/EXE/PowerShell transfer and execution, anti-VM checks, and C2 communication; multiple deceptive domains and IoCs were reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.