logo

CookieBomb Still Dropping Malicious Content

ID: e95ea82f-9228-5c45-b458-8fd11ab2253e

STIX ID: report--e95ea82f-9228-5c45-b458-8fd11ab2253e

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes the "Cookiebomb" drive-by infection campaign in which obfuscated JavaScript injected into legitimate websites creates cookies and hidden 1px iFrames, fingerprints browser plugin versions, performs multi-stage redirections to evade detection, and ultimately drops a trojanous executable; the report provides deobfuscated code, attack URLs, Fiddler session evidence, and a long list of compromised sites while noting low AV detection (7/45).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.