#CookieTime

Malware/Tool

2024-12-19 • Lazarus targets nuclear-related organization with new malware

CookieTime is malware found on hosts compromised in a Lazarus Group operation. Its delivery to Host A was not determined, but telemetry showed it running as the SQLExplorer service after LPEClient was installed. Earlier versions directly received and executed commands from a command-and-control server, while more recent use focused on downloading payloads. After lateral movement from Host A to Host C, CookieTime downloaded LPEClient, Charamel Loader, ServiceChanger, and an updated CookiePlus. CookieTime can also be delivered by Charamel Loader, which accepts a key and uses ChaCha20 to decrypt and load embedded resources.

Tagged Reports

« Back