#CookiePlus
Malware/Tool
2024-12-19 • Lazarus targets nuclear-related organization with new malware
CookiePlus is a modular Windows backdoor used by Lazarus in attacks on employees of a nuclear-related organization. It was loaded through Charamel Loader or ServiceChanger and disguised in some versions as a legitimate Notepad++ plugin or DirectX-related component. CookiePlus obtains its C2 configuration from an internal resource or external file, contacts the server to retrieve a Base64-encoded, RSA-encrypted payload, and decrypts and executes a DLL or one of several shellcodes. Reporting describes it as a possible MISTPEN successor.
-
2
Tagged Reports
-
2
Unique Authors
-
5
Active Days