CookiePlus is a newly identified Lazarus Group malware family described in the source material as a plugin-based downloader and modular backdoor, and assessed with medium confidence to be a successor to MISTPEN. It was observed in a DeathNote / Operation DreamJob intrusion targeting at least one nuclear-related organization, where Lazarus used fake recruiter-themed IT skills assessment lures and trojanized VNC software to infect victims. On Host C, CookiePlus was loaded by both ServiceChanger and Charamel Loader after Lazarus moved laterally from another compromised host. It was initially disguised as ComparePlus, an open-source Notepad++ plugin, and later samples were based on DirectX-Wrappers. CookiePlus can obtain its command-and-control server list either from internal resources or from an external file such as msado.inc. It encrypts host metadata with a hardcoded RSA public key, Base64-encodes it, and sends it to the C2 server as an HTTP cookie. It downloads additional payloads encrypted with ChaCha20 and supports delivery of both DLL payloads and shellcode payloads. Researchers recovered three CookiePlus-delivered shellcode plugins derived from DLLs converted with the open-source sRDI tool; observed plugins collected host information, controlled sleep behavior, and modified execution timing in configuration files. The campaign used compromised WordPress web servers running PHP-based services as C2 infrastructure, and CookiePlus was specifically noted among Lazarus malware families using such infrastructure. Supporting reporting also characterizes CookiePlus as a downloader with limited functionality that transmits minimal information from the infected host to the C2 server.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CookiePlus is a new plugin-based malicious program that we discovered during the investigation on Host C. ... Because CookiePlus acts as a downloader, it has limited functionality and transmits minimal information from the infected host to the C2 server.
"...deployment of a new modular backdoor referred to as CookiePlus..."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
If the value is 0xBEEF, CookiePlus checks whether the first four bytes of the payload are smaller than 0x80000000. If so, the shellcode in the payload is loaded after being granted execute permission.
The ServiceChanger malware stops a targeted legitimate service and then stores malicious files from its resource section to disk so that when the legitimate service is restarted, it loads the created malicious DLL via DLL side-loading. In this case, the targeted service was ssh-agent and the DLL file was libcrypto.dll.
When we first discovered CookiePlus, it was disguised as ComparePlus, an open source Notepad++ plugin... the most recent CookiePlus sample... is based on another open source project, DirectX-Wrappers
The ServiceChanger malware stops a targeted legitimate service and then stores malicious files from its resource section to disk so that when the legitimate service is restarted, it loads the created malicious DLL via DLL side-loading. In this case, the targeted service was ssh-agent and the DLL file was libcrypto.dll.
CookiePlus encodes the RSA-encrypted data using Base64. It is set as the cookie value in the HTTP header and passed to the C2.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular backdoor deployed in an infection chain attributed to Lazarus Group targeting a nuclear-related organization.
Named Lazarus malware referenced in a comparative table indicating use of RSA and plugin loading; no additional behavioral details provided in the content.
Newly discovered modular backdoor used in Lazarus 'Operation DreamJob' lures (fake skill assessment archives) to establish covert access on victim systems.
A new plugin-based Lazarus downloader that can obtain C2 configuration from internal resources or an external file, download and decrypt DLL or shellcode payloads with ChaCha20, execute plugins, and return encrypted results to C2. The report assesses it as a likely successor to MISTPEN.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.