WarmCookie, also known as BadSpace, is an actively developed Windows DLL backdoor first observed in 2024. It provides persistent remote access, profiles compromised hosts, receives operator commands, captures screenshots, executes shell commands, reads and writes files, and delivers and launches additional payloads. Later variants added execution handlers for PE files, DLLs, and PowerShell scripts. It uses encrypted HTTP-based command-and-control communications and incorporates anti-analysis checks, dynamically resolved APIs, encrypted strings, and legitimate-looking randomized names for persistence artifacts to hinder detection.
WarmCookie commonly establishes persistence through Windows Task Scheduler using COM interfaces and can execute with SYSTEM privileges. It has been distributed through recruiting and invoice-themed phishing, malspam, malvertising, and malicious-download chains. Observed infection flows have used CAPTCHA-gated landing pages and obfuscated JavaScript that invokes PowerShell and BITS to retrieve and launch the backdoor. CASTLEBOT/CastleLoader has also been reported as a distribution mechanism.
WarmCookie is used as an initial-access and post-compromise implant, frequently preceding deployment of tools such as Cobalt Strike and CSharp-Streamer-RAT. Activity involving WarmCookie/BadSpace has been assessed with high confidence as related to prior TA866 post-compromise operations, and its development has notable links to the Resident backdoor. Follow-on activity associated with this ecosystem has affected organizations internationally, with observed cases concentrated in the United States and particularly affecting manufacturing, government, and financial-services organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We assess with high confidence that recent post-compromise intrusion activity associated with WarmCookie/BadSpace is related to previous post-compromise activity that we attribute to TA866.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
"...a new backdoor “BadSpace”..."; "...the malware’s alias name WarmCookie."
Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
WARMCOOKIE uses legitimate-company names for "folder paths and scheduled task names"; its /u command-line parameter determines whether a scheduled task must be created.
Stage 1 copies the downloaded DLL ... at C:\ProgramData\RtlUpd\RtlUpd.dll. After the copy, the malware sets up persistence using COM with the Windows Task Scheduler.
New handlers provide "PowerShell script execution" and execute the temporary file using "PowerShell.exe."
The MITRE ATT&CK mapping explicitly lists "Command and Scripting Interpreter: Windows Command Shell."
WARMCOOKIE uses legitimate-company names for "folder paths and scheduled task names"; its /u command-line parameter determines whether a scheduled task must be created.
Once the CAPTCHA is solved, an obfuscated JavaScript file is downloaded from the page. WARMCOOKIE protects its strings using a custom string decryption algorithm.
It uses deceptive lures, such as job-related attachments, to trick users into executing malicious payloads.
The string bank is used "for defense evasion purposes, allowing the malware to relocate to more legitimate-looking directories."
This is done for defense evasion purposes, allowing the malware to relocate to more legitimate-looking directories.
The script defines rc4crypt(data, key) and iterates over references to decryption functions to recover strings: 'encrypted_data = data[offset+4:offset+4+length]' and 'dec_data = rc4crypt(encrypted_data,rc4_key)...decode()'.
This handler fingerprints and identifies the victim machines by collecting the IP address and CPU information.
The MITRE ATT&CK mapping explicitly lists "System Information Discovery."
The infrastructure linked to TAG-150 includes both victim-facing Tier 1 components, such as IP addresses and domains used as command-and-control (C2) servers for multiple malware families...
WARMCOOKIE samples communicate over HTTP with a hardcoded IP address ... The first request to the C2 server is sent through a GET request.
WARMCOOKIE can drop files on the victim machine; the threat actors provide the file path and file data.
148 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family distributed through malspam and malvertising. In the COM-focused example, it initializes COM and uses the legacy Task Scheduler 1.0 COM object via CLSID_CTaskScheduler and IID_ITaskScheduler to create a work item, configure flags, create a trigger, and establish persistence.
Named as a remote access trojan distributed by CastleLoader.
Previously distributed payload in TA584 activity; specific functionality not described in the provided content.
Previously used malware family in TA584 activity (mentioned historically).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.