Fake browser updates spread updated WarmCookie malware

Share:

A new ‘FakeUpdate’ campaign targeting users in France leverages compromised websites to show fake browser and application updates that spread a new version of the WarmCookie backdoor.

FakeUpdate is a cyberattack strategy used by a threat group known as ‘SocGolish’ who compromises or creates fake websites to show visitors fake update prompts for a variety of applications, such as web browsers, Java, VMware Workstation, WebEx, and Proton VPN.

When users click on update prompts designed to appear legitimate, a fake update is downloaded that drops a malicious payload, like info-stealers, cryptocurrency drainers, RATs, and even ransomware.

The latest campaign was discovered by researchers at Gen Threat Labs, who observed the WarmCookie backdoor being distributed as fake Google Chrome, Mozilla Firefox, Microsoft Edge, and Java updates.

WarmCookie, first discovered by eSentire in mid-2023, is a Windows backdoor recently seen distributed in phishing campaigns using fake job offers as lures.

Its broad capabilities include data and file theft, device profiling, program enumeration (via the Windows Registry), arbitrary command execution (via CMD), screenshot capturing, and the ability to introduce additional payloads on the infected system.

In the latest campaign spotted by Gen Threat Labs, the WarmCookie backdoor has been updated with new features, including running DLLs from the temp folder and sending back the output, as well as the ability to transfer and execute EXE and PowerShell files.

The lure used to trigger the infection is a fake browser update, which is common for FakeUpdate attacks. However, Gen Digital also found a site where a fake Java update was promoted in this campaign.

Fake browser and Java update prompts
Fake browser and Java update prompts
Source: BleepingComputer

The infection chain starts with the user clicking on a fake browser update notice, which triggers JavaScript that fetches the WarmCookie installer and prompts the user to save the file.

Latest infection change
Latest WarmCookie infection chain
Source: Gen Threat Labs

When the fake software update is executed, the malware performs some anti-VM checks to ensure it’s not running on an analyst’s environment and sends the newly infected system’s fingerprint to the command and control (C2) server, awaiting instructions.

Although Gen Threat Labs says the attackers use compromised websites in this campaign, some of the domains shared in the IoC section, like “edgeupdate[.]com” and “mozilaupgrade[.]com,” seem specifically selected to match the ‘FakeUpdate’ theme.

Remember, Chrome, Brave, Edge, Firefox, and all modern browsers are automatically updated when new updates become available.

A program restart may be needed for an update to be applied to the browser, but manually downloading and executing updater packages is never a part of an actual update process and should be seen as a sign of danger.

In many cases, FakeUpdates compromise legitimate and otherwise trustworthy websites, so these pop-ups should be treated with caution even when you’re on a familiar platform.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:43 pm, Jun 25, 2025
weather icon 26°C
L: 26° | H: 28°
overcast clouds
Humidity: 54 %
Pressure: 1010 mb
Wind: 7 mph SW
Wind Gust: 12 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
26° | 28°°C 0 mm 0% 6 mph 56 % 1010 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 23°°C 1 mm 100% 15 mph 83 % 1018 mb 0 mm/h
Fri Jun 27 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 13 mph 64 % 1023 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
17° | 31°°C 0 mm 0% 11 mph 79 % 1024 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
20° | 33°°C 0 mm 0% 11 mph 77 % 1024 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 6 mph 54 % 1010 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 26°°C 0 mm 0% 5 mph 51 % 1010 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 23°°C 0 mm 0% 4 mph 56 % 1009 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0.2 mm 20% 6 mph 77 % 1010 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 83 % 1009 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 8 mph 73 % 1010 mb 0 mm/h
Tomorrow 10:00 am
weather icon
23° | 23°°C 0 mm 0% 12 mph 54 % 1011 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
21° | 21°°C 0 mm 0% 12 mph 63 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,910.67
2.08%
Ethereum(ETH)
€2,084.23
-0.79%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.90
0.65%
Solana(SOL)
€125.76
0.31%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.142139
0.41%
Shiba Inu(SHIB)
€0.000010
-0.56%
Pepe(PEPE)
€0.000009
-1.71%
Scroll to Top