New Warmcookie Windows backdoor pushed via fake job offers
ID: 8d9c23d9-14f9-5463-8983-7b252af802b7
STIX ID: report--8d9c23d9-14f9-5463-8983-7b252af802b7
Feed Name: Bleeping Computer
Elastic Security Labs reports an active phishing campaign delivering the Warmcookie Windows backdoor via fake job/recruitment emails that redirect victims to pages prompting CAPTCHA and downloading an obfuscated JavaScript which runs a PowerShell script to use BITS and rundll32.exe to deploy C:\ProgramData\RtlUpd\RtlUpd.dll; the malware creates a scheduled task ('RtlUpd') to maintain persistence, fingerprints hosts, captures screenshots, enumerates installed software, executes commands, exfiltrates data via HTTP cookie parameters, and can drop additional payloads — the campaign is ongoing with new domains spun up weekly and was previously observed by eSentire in 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
