STALECOOKIE
STALECOOKIE is an Android malware used in Russia-linked operations targeting Ukrainian military/government users and battlefield technology. It has been reported as masquerading as Ukraine’s DELTA battlefield management platform (and more broadly mimicking battlefield management platforms) to socially engineer installation/use, with the primary described capability of stealing browser cookies from infected Android devices. The activity is associated in reporting with Russian threat clusters UNC4221 (UAC-0185) and also mentioned alongside UNC5792 (UAC-0195) as part of malware deployed in these campaigns. In the same operational context, STALECOOKIE is referenced together with other Android tooling (e.g., TINYWHALE and MeshAgent) used to enable remote management, but the specific behavior explicitly attributed to STALECOOKIE in the provided content is cookie theft via DELTA-themed impersonation.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5792 and UNC4221 ... deploy malware including STALECOOKIE and TINYWHALE.
"...leveraged an Android malware called STALECOOKIE that mimics Ukraine's battlefield management platform DELTA to steal browser cookies."
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android-targeting malware used to steal cookies and facilitate remote management/access.
Malware deployed following account-hijack/phishing activity abusing Signal/WhatsApp features (no further functional detail provided).
Android malware that impersonates the DELTA battlefield management platform to steal browser cookies.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.