New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers
ID: 79463e68-6c5e-59aa-8830-81dcaa33fa3f
STIX ID: report--79463e68-6c5e-59aa-8830-81dcaa33fa3f
Feed Name: The Hacker News
Researchers disclosed an active global phishing campaign (tracked as REF6127) leveraging recruitment-themed emails and compromised infrastructure to deliver a Windows backdoor called WARMCOOKIE. Victims are lured to download an HTML/JS payload that runs obfuscated PowerShell to abuse BITS and fetch a DLL backdoor compiled with hard-coded C2 IP and RC4 key; WARMCOOKIE establishes persistence, performs anti-analysis and host fingerprinting, captures screenshots, executes commands, manipulates files, and is used to stage additional payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
