CookieBag

First seen
2021-02-15 00:00:00
Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:46:50

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:uk

Context

CookieBag is a credential-stealing malware family that targets financial and government sectors, primarily aiming to collect sensitive information and credentials. Its operations have been noted in the United States and the United Kingdom.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cookiebag_Auto (yara-rule)

Reports & references

  • github.com — Appendix%20C%20(Digital)%20 %20The%20Malware%20Arsenal (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cookiebag (report)

External references