WarmCookie

Aliases: Badspace, Carrotstick, QUICKBIND

Malware type
backdoor, screen-capture, trojan
Family
Malware family
Last IoC activity
2026-07-21 00:33:49
Profile updated
2026-07-07 13:14:13

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots. It communicates with a command and control (C&C) server via HTTP to receive further instructions and exfiltrate stolen data. It is commonly distributed through phishing campaigns and malicious downloads, targeting unsuspecting users to infiltrate systems undetected.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Warmcookie_Auto (yara-rule)

Reports & references

  • securityintelligence.com — Hive0137 On Ai Journey (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • go.recordedfuture.com — Cta 2025 0130 (report)
  • x.com — 1840762181668741130 (report)
  • Cisco Talos — Highlighting Ta866 Asylum Ambuscade (report)
  • Cisco Talos — Warmcookie Analysis (report)
  • esentire.com — Esentire Threat Intelligence Malware Analysis Resident Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Warmcookie (report)
  • vertex.link — Categorizing Software With Code Families (report)
  • github.com — Windows Trojan Warmcookie.Yar (report)
  • darktrace.com — Disarming The Warmcookie Backdoor Darktraces Oven Ready Solution (report)
  • gdatasoftware.com — 37947 Badspace Backdoor (report)
  • hunt.io — From Warm To Burned Shedding Light On Updated Warmcookie Infrastructure (report)
  • elastic.co — Dipping Into Danger (report)
  • elastic.co — Revisiting Warmcookie (report)
  • github.com — Badspace.Py (report)
  • github.com — Badspace.Py (report)
  • community.emergingthreats.net — 1630 (report)
  • github.com — Vb2024%20 %20Getting%20Cozy%20With%20Milk%20And%20Warmcookies (report)

External references