An ongoing fake Google Chrome update effort targeting France has been noticed, which spreads WarmCookie malware via compromised websites. WarmCookie is a Windows malware that is used to obtain system access through phishing operations.
It is a two-stage backdoor intended to spread more payloads and examine target networks. It most commonly spreads through phishing efforts that impersonate job offers.
Warm cookies can be used as fingerprint machines, take screenshots, exfiltrate stolen data, read and write files, and interact with a command and control (C&C) server to get commands.
Gen Threat Labs claims that WarmCookie has also been updated.
Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free
The latest version supports the following commands:
WarmCookie malware is downloaded when a user clicks on the FakeUpdate-infected webpage. Once installed, it contacts C&C for further operations, takes a screenshot, executes the command, and steals data from the disk.
In June, Elastic Security Labs released a report on a phishing effort that uses lures related to jobs and recruitment to spread WarmCookie malware.
Since the end of April, attack chains have been noticed, and email messages from employment agencies such as Hays, Michael Page, and PageGroup have been used to persuade recipients to click on an embedded link to access information about a job opportunity.
Hence, by taking proactive actions to check the credibility of updates and adopting robust safety solutions, users may considerably decrease the chance of falling prey to such sophisticated attacks.
Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Webinar
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…