Resident
Resident is a backdoor malware family referenced by Cisco Talos as having significant code and functional overlaps with WarmCookie (also known as BadSpace). High-confidence similarities reported between Resident and WarmCookie include identical RC4 decryption implementations, similar mutex management using GUID-like mutex strings, and similar persistence mechanisms. Talos assessed these overlaps as indicating likely shared authorship, with possible links to the TA866 threat actor. The provided content does not describe Resident’s full standalone infection vector or complete capability set directly, but it does establish Resident as a backdoor malware related in development lineage to WarmCookie.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its infection chains and functionality highlight notable development links to Resident backdoor, indicating possible shared authorship by TA866.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor malware family that shares notable code/function-level similarities with WarmCookie (e.g., RC4 implementation, mutex management, persistence mechanisms), suggesting shared development lineage.
Resident is a backdoor malware family noted here for code and functional similarities with WarmCookie, including RC4 implementation, mutex handling, startup logic, and persistence via scheduled tasks.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.