A new widely used backdoor has been observed known by the name WarmCookie backdoor. WarmCookie backdoor is a purpose-built Windows malware that is distributed through phishing emails.
The backdoor campaign, identified as REF6127, targets individuals using themes related to recruitment and job opportunities. Attackers craft their bait based on the victims' current employers, tempting them with potential new job offers. They then send phishing emails to the victims, which include links purportedly leading to internal systems where job descriptions can be viewed. Clicking the link initiates the deployment of WarmCookie by running PowerShell.
WarmCookie is an initial backdoor tool used to infiltrate victim networks, gathering victim information, capturing screenshots, fingerprinting a machine and deploying additional payloads. Its code shares similarities with a previously identified sample, but the latest version poses a greater threat. Once initial access is gained, attackers can proceed to deploy more destructive payloads, such as ransomware. The backdoor also performs anti-analysis checks to avoid detection.
The campaign is ongoing with threat actors actively sending phishing emails to their victims.
To protect against the backdoor, it is recommended to take the following measures:
[caption id="attachment_6672" align="alignnone" width="516"]
References: