Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (2024)

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (1)

Looking for a new job is hard enough as it is but now hackers are using a phishing campaign to infect job seekers with a new Windows-based backdoor.

As reported by The Hacker News, the backdoor in question has been dubbed WARMCOOKIE by researchers at the cybersecurity firm Elastic Security Labs. According to a new report, it’s used to “scout out victim networks and deploy additional payloads.”

Once installed on a victim’s PC, the backdoor can fingerprint infected machines, capture screenshots and drop other Windows malware onto their system.

Here’s everything you need to know about this new Windows backdoor and how you can stay safe when looking for a new job online.

WARMCOOKIE backdoor

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (2)

This campaign began at the end of April and uses emails that claim to come from recruitment firms such as Hays, Michael Page and PageGroup in its attack chain. These emails try to entice recipients into clicking on an embedded link to view additional details about a job opportunity.

If a potential victim does click on the link contained in these emails, they are then told to download a document by solving a CAPTCHA challenge. Doing so drops a malicious JavaScript file on their PC. It’s worth noting that this campaign uses compromised websites to host its initial phishing URLs which are then used to redirect potential victims to malicious landing pages.

According to Elastic, this obfuscated script runs PowerShell and loads the WARMCOOKIE backdoor onto their PC. The backdoor follows a two-step process which allows for it to establish persistence on the now compromised PC but before doing so, it performs anti-analysis checks to avoid being detected.

Sign up to get the BEST of Tom’s Guide direct to your inbox.

Upgrade your life with a daily dose of the biggest tech news, lifestyle hacks and our curated analysis. Be the first to know about cutting-edge gadgets and the hottest deals.

Besides capturing information from the infected PC, WARMCOOKIE can also read and write to files, execute commands using cmd.exe, compile a list of installed applications and capture screenshots.

This backdoor doesn’t use automation to install malware onto a Windows PC. Instead, it walks victims through a number of different prompts that hide the intentions of the hackers behind this campaign that ultimately results in their computer being compromised and infected with malware.

How to stay safe from Windows malware

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (3)

Windows malware comes in many different forms but fortunately, the steps you can take to keep you and your PC safe remain the same across different malware strains.

For starters, you want to ensure that Windows Defender is enabled and up to date. This free antivirus software comes pre-installed on all Windows 10 and Windows 11 PCs in the same way that Apple includes its own X-Protect antivirus software with macOS. For additional protection though and some useful extras like a VPN or password manager, you should also consider installing one of the best antivirus software suites to run alongside it.

From here, you want to be extra careful when checking your inbox. This involves carefully scrutinizing senders’ email addresses to make sure they are legitimate and avoiding downloading any attachments or clicking on links from unknown senders. Hackers use malicious documents and other bogus attachments as an entryway into your PC, so if you don’t know the sender, you should avoid downloading anything that’s sent to you.

As for staying safe during a job hunt, you want to stick to established and trusted sites and services like Indeed, LinkedIn, ZipRecruiter, Monster and GlassDoor. Likewise, if possible, you should try to use your existing connections to see if there are any new positions or opportunities available before heading to a job site to look for work.

WARMCOOKIE may be a newly discovered backdoor but it is quickly gaining popularity among hackers and other cybercriminals as it provides an easy way to infect vulnerable PCs with other types of malware. As such, this likely isn’t the last time that we’ll hear about this particular backdoor being used in cyberattacks.

More from Tom's Guide

  • Frontier hack exposed personal info of 750,000 customers including SSNs
  • LightSpy spyware can now snoop on your Mac and your iPhone
  • Over 500 million hit in massive Ticketmaster data breach — what to do now

Network

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (4)

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (5)

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (6)

Contract Length

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (7)

Showing 2 of 2 deals

Filters

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (8)

Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (11)

Anthony Spadafora

Senior Editor Security and Networking

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about malware and adware

Hackers are using fake Chrome, Word and OneDrive errors to trick people into installing malware — how to stay safeUrgent Windows security flaw lets hackers infect your PC over Wi-Fi — update right now

Latest

4th of July mattress sales 2024: top 7 early deals — plus everything you need to know
See more latest►

No comments yetComment from the forums

    Most Popular
    Fujifilm just launched the Instax Wide 400 — and it's been 10 years in the making
    New Apple CarPlay report spills all the details on new features and how it will work
    Sony confirms a new 'Uncharted' is on the way — but not the one we want
    Your Apple Watch just got a surprise new sleep feature in watchOS 11 — here’s what we know
    Sleep Number has released its most affordable smart mattress yet – and prices start at just $599
    One of my favorite Netflix movies is getting a surprise sequel — and you can stream the original right now
    This AI model is learning to speak by watching videos — here's how
    Prime Video just added one of my favorite historical dramas — and it’s 93% on Rotten Tomatoes
    YouTube is experimenting with Twitter-esque Community Notes
    5 best adult animated shows on Netflix to stream right now
    NYT Strands today — hints, spangram and answers for game #107 (Tuesday, June 18 2024)
    Hackers target job hunters with dangerous new Windows backdoor — how to stay safe (2024)

    References

    Top Articles
    Latest Posts
    Article information

    Author: Corie Satterfield

    Last Updated:

    Views: 5334

    Rating: 4.1 / 5 (62 voted)

    Reviews: 93% of readers found this page helpful

    Author information

    Name: Corie Satterfield

    Birthday: 1992-08-19

    Address: 850 Benjamin Bridge, Dickinsonchester, CO 68572-0542

    Phone: +26813599986666

    Job: Sales Manager

    Hobby: Table tennis, Soapmaking, Flower arranging, amateur radio, Rock climbing, scrapbook, Horseback riding

    Introduction: My name is Corie Satterfield, I am a fancy, perfect, spotless, quaint, fantastic, funny, lucky person who loves writing and wants to share my knowledge and understanding with you.