WarmCookie, also known as BadSpace, is a Windows backdoor first publicly reported in 2024 and associated with financially motivated intrusion activity. It is used to establish long-term access on compromised systems, communicate with command-and-control infrastructure, execute follow-on payloads, and support broader post-compromise operations. Reported follow-on tooling includes Cobalt Strike and CSharp-Streamer-RAT, and multiple assessments link WarmCookie activity to TA866, with code and functional similarities also noted between WarmCookie and the Resident backdoor.
WarmCookie has been distributed through malspam, phishing lures, malicious downloads, and malvertising. Observed lures have included invoice-themed and job or recruiting-themed content, with infection chains using obfuscated JavaScript and PowerShell to retrieve and execute the malware. More recent reporting also places WarmCookie within broader malware delivery ecosystems, including distribution by CastleBot or CastleLoader in some campaigns.
On execution, WarmCookie is designed to maintain persistence and provide remote access. Persistence has been observed via Windows Task Scheduler, including use of COM-based Task Scheduler interfaces and scheduled-task creation with increasingly randomized naming intended to blend with legitimate software. Newer variants use randomized string banks of legitimate company names for folders and task names, GUID-like mutexes, and other code changes intended to improve stealth and resilience.
WarmCookie has evolved beyond basic backdoor functionality. Reported capabilities include downloading and executing additional payloads, executing PE files, DLLs, and PowerShell scripts, self-update behavior, and removal or disabling of its own persistence. Its operators have also modified network and execution characteristics over time to reduce detection, including more legitimate-looking user-agent strings and infrastructure changes. The malware remains under active development and has continued operating despite law-enforcement disruption efforts such as Operation Endgame.
Victimology associated with WarmCookie-linked intrusion activity has included organizations in multiple sectors, with manufacturing, government, and financial services among the reported affected industries. The malware is best characterized as an actively maintained Windows backdoor used as both an access mechanism and a delivery platform for secondary malware in cybercriminal intrusion campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We assess with high confidence that recent post-compromise intrusion activity associated with WarmCookie/BadSpace is related to previous post-compromise activity that we attribute to TA866.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
"...a new backdoor “BadSpace”..."; "...the malware’s alias name WarmCookie."
Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Qakbot was frequently distributed through phishing emails, including hijacked email threads... WarmCookie, also known as BadSpace, is a malware family... being distributed through malspam and malvertising.
Gh0stRAT/SimpleRemoter code creating a scheduled task through Task Scheduler COM interfaces... WarmCookie initializes COM, creates the older Task Scheduler 1.0 object using CLSID_CTaskScheduler, and requests IID_ITaskScheduler. It then creates a work item, configures flags and creates a trigger.
WarmCookie leverages Task Scheduler to achieve persistence, creating scheduled tasks under %ALLUSERSPROFILE% or %ALLDATA%, and re-executing itself after a 60-second delay.
The obfuscated JavaScript downloader, often delivered as a compressed ZIP, triggers a PowerShell command
We identified four new handlers ... providing quick capabilities to launch executables, DLLs, and scripts: ... PowerShell script execution ... Then, it executes the temporary file directly or uses either rundll32.exe or PowerShell.exe.
Malware and MITRE ATT&CK ... Techniques ... Command and Scripting Interpreter: Windows Command Shell.
The obfuscated JavaScript downloader, often delivered as a compressed ZIP, triggers a PowerShell command
The obfuscated JavaScript downloader, often delivered as a compressed ZIP, triggers a PowerShell command that uses Bitsadmin to download and execute the WarmCookie DLL
Warm Cookie - is a backdoor distributed via phishing emails and malicious downloads. It uses deceptive lures, such as job-related attachments, to trick users into executing malicious payloads.
Gh0stRAT/SimpleRemoter code creating a scheduled task through Task Scheduler COM interfaces... WarmCookie initializes COM, creates the older Task Scheduler 1.0 object using CLSID_CTaskScheduler, and requests IID_ITaskScheduler. It then creates a work item, configures flags and creates a trigger.
WarmCookie leverages Task Scheduler to achieve persistence, creating scheduled tasks under %ALLUSERSPROFILE% or %ALLDATA%, and re-executing itself after a 60-second delay.
Gh0stRAT/SimpleRemoter code creating a scheduled task through Task Scheduler COM interfaces... WarmCookie initializes COM, creates the older Task Scheduler 1.0 object using CLSID_CTaskScheduler, and requests IID_ITaskScheduler. It then creates a work item, configures flags and creates a trigger.
The script searches for decryption-function byte patterns and extracts an RC4 key and encrypted blob from memory before decrypting it, indicating the malware stores strings in encrypted form.
It uses deceptive lures, such as job-related attachments, to trick users into executing malicious payloads.
"New variants now embed two separate GUID-like mutexes, which are used for better control over initialization and synchronization"
This is done for defense evasion purposes, allowing the malware to relocate to more legitimate-looking directories.
The script defines rc4crypt(data, key) and iterates over references to decryption functions to recover strings: 'encrypted_data = data[offset+4:offset+4+length]' and 'dec_data = rc4crypt(encrypted_data,rc4_key)...decode()'.
The infrastructure linked to TAG-150 includes both victim-facing Tier 1 components, such as IP addresses and domains used as command-and-control (C2) servers for multiple malware families...
Captured screenshots are transmitted to the attacker’s C2 server ... via HTTP POST requests.
141 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family distributed through malspam and malvertising. In the COM-focused example, it initializes COM and uses the legacy Task Scheduler 1.0 COM object via CLSID_CTaskScheduler and IID_ITaskScheduler to create a work item, configure flags, create a trigger, and establish persistence.
Named as a remote access trojan distributed by CastleLoader.
Previously distributed payload in TA584 activity; specific functionality not described in the provided content.
Previously used malware family in TA584 activity (mentioned historically).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.