HomeSecurityWarmCookie malware: Infects users through malvertising / malspam campaigns

WarmCookie malware: Infects users through malvertising/malspam campaigns

A new malware, named WarmCookie, has been distributed via malspam and malvertising campaigns since April 2024.

WarmCookie malware

According to a new post from Cisco Talos, the malware facilitates long-term access to compromised networks and has been observed as an initial payload, often leading to the deployment of other malware, such as CSharp-Streamer-RAT and Cobalt Strike.

WarmCookie: How it infects systems

WarmCookie campaigns use various baits, such as job postings or invoices, to lure victims into clicking on malicious links. These campaigns often deliver the WarmCookie malware via emails with malicious attachments or links that initiate the infection process.

See also: GHOSTPULSE Malware embeds itself in PNG files

The malware itself is capable of executing commands, taking screenshots, and deploying additional payloads, allowing control of compromised systems.

TA866 hackers and Resident Backdoor

According to Cisco Talos, the WarmCookie malware is likely associated with a threat group known as TA866, which has been active since 2023. WarmCookie also has similarities to the Resident backdoor, which was previously used by the TA866 group. Researchers observed similarities in core functionality and code, suggesting that both malware families were likely developed by the same group.

However, according to researchers, WarmCookie is much more powerful and supports more commands compared to the Resident backdoor.

See also: Latrodectus malware is back – New phishing attacks

Evolution of the WarmCookie malware

The WarmCookie infection chain typically begins with malicious JavaScript downloaders delivered either via malspam or malvertising.Once executed, these scripts retrieve the WarmCookie payload, allowing attackers to maintain permanent access to the compromised environment.

The latest samples observed by Cisco Talos show that WarmCookie is evolving and researchers expect that threat actors will continue to improve its functionality.

WarmCookie malware

Protection

The above shows that a series of measures are necessary to protect against WarmCookie malware. First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from such attacks.

Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.

See also: WordPress sites hacked: Fake plugins promote info-stealer malware

Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS