The WarmCookie Malware Campaign: A Sneaky Threat Posed by Fake Browser Updates
ID: 7f116428-c363-586d-80e0-c7c0bdcce6c8
STIX ID: report--7f116428-c363-586d-80e0-c7c0bdcce6c8
Feed Name: SOCRadar Blog
The WarmCookie campaign uses compromised websites to display fake Chrome/Firefox update prompts that trick victims into installing malware which performs anti-VM checks, device fingerprinting, credential harvesting, screenshot capture, keystroke logging, command execution, and data exfiltration. Attackers deliver varied payloads—including info-stealers, remote access tools, and ransomware—targeting multiple sectors and leveraging JavaScript/HTML obfuscation and social engineering to evade traditional security tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
