WarmCookie
Aliases: Badspace, Carrotstick, QUICKBIND
- Malware type
- backdoor, screen-capture, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-21 00:33:49
- Profile updated
- 2026-07-07 13:14:13
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots. It communicates with a command and control (C&C) server via HTTP to receive further instructions and exfiltrate stolen data. It is commonly distributed through phishing campaigns and malicious downloads, targeting unsuspecting users to infiltrate systems undetected.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Warmcookie_Auto (yara-rule)
Reports & references
- securityintelligence.com — Hive0137 On Ai Journey (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- go.recordedfuture.com — Cta 2025 0130 (report)
- x.com — 1840762181668741130 (report)
- Cisco Talos — Highlighting Ta866 Asylum Ambuscade (report)
- Cisco Talos — Warmcookie Analysis (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Resident Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Warmcookie (report)
- vertex.link — Categorizing Software With Code Families (report)
- github.com — Windows Trojan Warmcookie.Yar (report)
- darktrace.com — Disarming The Warmcookie Backdoor Darktraces Oven Ready Solution (report)
- gdatasoftware.com — 37947 Badspace Backdoor (report)
- hunt.io — From Warm To Burned Shedding Light On Updated Warmcookie Infrastructure (report)
- elastic.co — Dipping Into Danger (report)
- elastic.co — Revisiting Warmcookie (report)
- github.com — Badspace.Py (report)
- github.com — Badspace.Py (report)
- community.emergingthreats.net — 1630 (report)
- github.com — Vb2024%20 %20Getting%20Cozy%20With%20Milk%20And%20Warmcookies (report)