A new malware, named WarmCookie, has been distributed via malspam and malvertising campaigns since April 2024.

According to a new post from Cisco Talos, the malware facilitates long-term access to compromised networks and has been observed as an initial payload, often leading to the deployment of other malware, such as CSharp-Streamer-RAT and Cobalt Strike.
WarmCookie: How it infects systems
WarmCookie campaigns use various baits, such as job postings or invoices, to lure victims into clicking on malicious links. These campaigns often deliver the WarmCookie malware via emails with malicious attachments or links that initiate the infection process.
See also: GHOSTPULSE Malware embeds itself in PNG files
The malware itself is capable of executing commands, taking screenshots, and deploying additional payloads, allowing control of compromised systems.
TA866 hackers and Resident Backdoor
According to Cisco Talos, the WarmCookie malware is likely associated with a threat group known as TA866, which has been active since 2023. WarmCookie also has similarities to the Resident backdoor, which was previously used by the TA866 group. Researchers observed similarities in core functionality and code, suggesting that both malware families were likely developed by the same group.
However, according to researchers, WarmCookie is much more powerful and supports more commands compared to the Resident backdoor.
See also: Latrodectus malware is back – New phishing attacks
Evolution of the WarmCookie malware
The WarmCookie infection chain typically begins with malicious JavaScript downloaders delivered either via malspam or malvertising.Once executed, these scripts retrieve the WarmCookie payload, allowing attackers to maintain permanent access to the compromised environment.
The latest samples observed by Cisco Talos show that WarmCookie is evolving and researchers expect that threat actors will continue to improve its functionality.

Protection
The above shows that a series of measures are necessary to protect against WarmCookie malware. First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from such attacks.
Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.
See also: WordPress sites hacked: Fake plugins promote info-stealer malware
Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.
Source: www.infosecurity-magazine.com
