Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 20, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
WarmCookie, also known as BadSpace, is an actively developed Windows DLL backdoor first observed in 2024.
Profile source: Mallory opens in a new tabWarmCookie
WarmCookie, also known as BadSpace, is an actively developed Windows DLL backdoor first observed in 2024. It provides persistent remote access, profiles compromised hosts, receives operator commands, captures screenshots, executes shell commands, reads and writes files, and delivers and launches additional payloads. Later variants added execution handlers for PE files, DLLs, and PowerShell scripts. It uses encrypted HTTP-based command-and-control communications and incorporates anti-analysis checks, dynamically resolved APIs, encrypted strings, and legitimate-looking randomized names for persistence artifacts to hinder detection.
WarmCookie commonly establishes persistence through Windows Task Scheduler using COM interfaces and can execute with SYSTEM privileges. It has been distributed through recruiting and invoice-themed phishing, malspam, malvertising, and malicious-download chains. Observed infection flows have used CAPTCHA-gated landing pages and obfuscated JavaScript that invokes PowerShell and BITS to retrieve and launch the backdoor. CASTLEBOT/CastleLoader has also been reported as a distribution mechanism.
WarmCookie is used as an initial-access and post-compromise implant, frequently preceding deployment of tools such as Cobalt Strike and CSharp-Streamer-RAT. Activity involving WarmCookie/BadSpace has been assessed with high confidence as related to prior TA866 post-compromise operations, and its development has notable links to the Resident backdoor. Follow-on activity associated with this ecosystem has affected organizations internationally, with observed cases concentrated in the United States and particularly affecting manufacturing, government, and financial-services organizations.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
We assess with high confidence that recent post-compromise intrusion activity associated with WarmCookie/BadSpace is related to previous post-compromise activity that we attribute to TA866.
These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...
"...a new backdoor “BadSpace”..."; "...the malware’s alias name WarmCookie."
Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.