Skip to content

WarmCookie

WarmCookie, also known as BadSpace, is a Windows backdoor malware family first reported as emerging in April 2024.

Profile source: Mallory opens in a new tab

WarmCookie

Family profile

WarmCookie, also known as BadSpace, is a Windows backdoor malware family first reported as emerging in April 2024. It has been distributed through malspam, malvertising, phishing emails, malicious downloads, and recruiting-, invoice-, and job-themed lures, often using obfuscated JavaScript delivered in ZIP archives that launches PowerShell and Bitsadmin to download and execute a WarmCookie DLL. It has also been observed delivered by other malware distribution ecosystems including CastleLoader/CASTLEBOT. WarmCookie is designed to provide long-term access to compromised environments, enable remote access, data theft, and deployment of additional payloads. Reported follow-on payloads include CSharp-Streamer-RAT and Cobalt Strike, and it has also been referenced as a secondary payload in broader loader ecosystems.

WarmCookie establishes persistence via Windows Task Scheduler. Reporting specifically notes use of the legacy Task Scheduler 1.0 COM interfaces for persistence, as well as scheduled tasks created under paths such as %ALLUSERSPROFILE% or %ALLDATA%, with re-execution after a 60-second delay. Newer variants changed the scheduled-task execution parameter from /p to /u and use randomized folder and task names derived from a "string bank" of legitimate company names to improve evasion. Recent variants also introduced dual GUID-like mutexes, campaign IDs embedded since July 2024, and additional execution handlers for EXE, DLL, and PowerShell payloads, including DLL execution via rundll32.exe with a Start export. Elastic reported that payloads are written to temporary directories before execution and that some builds support self-update and persistence removal commands.

Cisco Talos assessed with high confidence that recent WarmCookie/BadSpace post-compromise activity is related to TA866 (also known as Asylum Ambuscade), and Talos further assessed that WarmCookie likely shares authorship with the Resident backdoor based on code and functional similarities including RC4 decryption and mutex handling. Proofpoint also reported TA584 using WarmCookie in 2024, and Recorded Future linked WarmCookie infrastructure and delivery to TAG-150/GrayBravo-associated CastleLoader activity. Victimology associated with TA866-linked follow-on activity was concentrated in the United States, with manufacturing the most affected sector, followed by government and financial services.

Infrastructure and clustering details reported for WarmCookie include campaign IDs such as traffic1, traffic2, lod2lod, capo, and PrivateDLL; RC4 keys including 83ddc084e21a244c, fd1285af2130, and ac180d12b62a; and a likely reused default SSL certificate across C2 infrastructure with SHA1 fingerprint e88727d4f95f0a366c2b3b4a742950a14eff04a4 and SHA256 fingerprint 8c5522c6f2ca22af8db14d404dbf5647a1eba13f2b0f73b0a06d8e304bd89cc0. Reported C2-related indicators include the domain storsvc-win[.]com and the IP 192[.]36[.]57[.]164. WarmCookie was also named among malware families targeted by Europol's Operation Endgame actions in May 2025, but subsequent reporting indicates the malware remained active and continued to evolve.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • Scalaxy B.V.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
TA866

We assess with high confidence that recent post-compromise intrusion activity associated with WarmCookie/BadSpace is related to previous post-compromise activity that we attribute to TA866.

TAG-150

These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...

SocGholish

"...a new backdoor “BadSpace”..."; "...the malware’s alias name WarmCookie."

TA584

Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT.

MITRE ATT&CK

WarmCookie in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.