A new “FakeUpdate” campaign targeting users in France leverages compromised websites to display fake browser and application updates that spread a new version of the WarmCookie malware.
See also: SnipBot: New version of RomCom malware steals data

FakeUpdate is a cyberattack strategy used by a threat group known as "SocGolish," which compromises or creates fake websites to show visitors fake update messages for a variety of applications, including web browsers, Java, VMware Workstation, WebEx , and Proton VPN.
When users click on update prompts designed to appear legitimate, a fake update is downloaded that drops a malicious payload, such as infostealers, cryptocurrency drainers, RATs, and even ransomware.
The latest campaign was discovered by researchers at Gen Threat Labs, who observed the WarmCookie malware being distributed via fake Google Chrome, Mozilla Firefox, Microsoft Edge , and Java.
WarmCookie, first discovered by eSentire in mid-2023, is a Windows that has recently been distributed in phishing using fake job offers as a lure.
Its extensive capabilities include data and file theft, device profiling, program enumeration via the Windows registry, arbitrary command execution via CMD, screenshot capture, as well as the ability to inject additional payloads into the infected system.
In the latest campaign discovered by Gen Threat Labs, the WarmCookie malware has gained updated capabilities. It can now execute DLLs from the temp folder and send the output back, while also being able to transfer and execute EXE and PowerShell files.
See also: Fake CAPTCHA requests contain malware
The lure used to trigger the infection is a fake browser update, which is common for FakeUpdate attacks. However, Gen Digital also found a website where a fake Java update was promoted in this campaign.

The infection chain begins when the user clicks on a fake browser update notification. This triggers JavaScript, which retrieves the WarmCookie installer and prompts the user to save the file.
When the fake software update is executed, the WarmCookie malware performs some anti-VM checks to ensure that it is not running in an analyst and sends the fingerprint of the newly infected system to the command and control (C2) server, awaiting instructions.
Although Gen Threat Labs says that the attackers are using compromised websites in this campaign, some of the domains shared in the IoC section, such as “edgeupdate[.]com” and “mozilaupgrade[.]com,” appear to have been specifically chosen to fit the “FakeUpdate”.
Remember that Chrome, Brave, Edge, Firefox, and all modern browsers update automatically when new updates are available.
A program restart may be required to apply an update to the browser, but manually downloading and running update packages is never part of a true update process and should be considered a sign of danger.
In many cases, FakeUpdates infect legitimate and otherwise trustworthy websites, so these pop-ups should be treated with caution even when you are on a familiar platform.
See also: Hackers hide malware in fake 'deleted Diddy files'
Malware, such as WarmCookie, is designed to harm a computer, server, client, or computer network. Different types of malware include viruses, worms, trojans, ransomware, spyware, adware, and more. These malicious programs can infiltrate systems through various methods, such as email attachments, software downloads, or visiting infected sites. Once inside, malware can steal, encrypt, or delete sensitive data, change or disrupt basic computer functions, and monitor users' computer activity without permission. Protecting against malware includes using antivirus software, keeping systems up-to-date, and practicing safe browsing habits. Understanding the risks associated with malware is crucial for both individuals and organizations to protect their digital environment.
Source: bleepingcomputer
