Skip to content

WarmCookie

WarmCookie, also known as BadSpace, is an actively developed Windows DLL backdoor first observed in 2024.

Profile source: Mallory opens in a new tab

WarmCookie

Family profile

WarmCookie, also known as BadSpace, is an actively developed Windows DLL backdoor first observed in 2024. It provides persistent remote access, profiles compromised hosts, receives operator commands, captures screenshots, executes shell commands, reads and writes files, and delivers and launches additional payloads. Later variants added execution handlers for PE files, DLLs, and PowerShell scripts. It uses encrypted HTTP-based command-and-control communications and incorporates anti-analysis checks, dynamically resolved APIs, encrypted strings, and legitimate-looking randomized names for persistence artifacts to hinder detection.

WarmCookie commonly establishes persistence through Windows Task Scheduler using COM interfaces and can execute with SYSTEM privileges. It has been distributed through recruiting and invoice-themed phishing, malspam, malvertising, and malicious-download chains. Observed infection flows have used CAPTCHA-gated landing pages and obfuscated JavaScript that invokes PowerShell and BITS to retrieve and launch the backdoor. CASTLEBOT/CastleLoader has also been reported as a distribution mechanism.

WarmCookie is used as an initial-access and post-compromise implant, frequently preceding deployment of tools such as Cobalt Strike and CSharp-Streamer-RAT. Activity involving WarmCookie/BadSpace has been assessed with high confidence as related to prior TA866 post-compromise operations, and its development has notable links to the Resident backdoor. Follow-on activity associated with this ecosystem has affected organizations internationally, with observed cases concentrated in the United States and particularly affecting manufacturing, government, and financial-services organizations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 20, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • Eonix Corporation1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
TA866

We assess with high confidence that recent post-compromise intrusion activity associated with WarmCookie/BadSpace is related to previous post-compromise activity that we attribute to TA866.

TAG-150

These malware families are frequently observed as initial infection vectors that deliver a wide range of secondary payloads, including SectopRAT, WarmCookie, HijackLoader, NetSupport RAT...

Mustard Tempest

"...a new backdoor “BadSpace”..."; "...the malware’s alias name WarmCookie."

TA584

Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT.

MITRE ATT&CK

WarmCookie in ATT&CK

34 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.