Skip to content

Malware

WarmCookie

aka Badspace · Carrotstick · QUICKBIND

WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots.

WarmCookie, also known as Badspace, Carrotstick, QUICKBIND, is a Windows malware family.

Background

WarmCookie is a backdoor that can run commands, read and write files, and grab screenshots. Over HTTP, it reaches a command and control (C&C) server to fetch additional instructions and send out stolen information. It typically arrives via phishing campaigns and malicious downloads, slipping onto the systems of unsuspecting users without raising alarm.


Source: Malpedia (Fraunhofer FKIE).