JsonCookies is a simple tool used by the Cycldek hackers, an Advanced Persistent Threat actor that is believed to be located in China. JsonCookies is one of the more basic utilities in Cycldek's arsenal, but it serves a very important purpose – it is able to extract cookies from the SQLite databases that Google Chrome and Chromium-based Web browsers use.
The JsonCookies implant does not look for a particular cookie type and, instead, it dumps the whole databases by listing the ID, cookie name, cookie value, and the domain name that these values correspond to. All of the data is stored in a file 'FuckCookies.txt' that is exported to the Command and Control server as soon as the attack is completed.
This is a proprietary tool whose author did not mean to be used for harmful purposes. However, cybercriminals adapt and modify such projects to fit their nefarious needs frequently.
Use SpyHunter to Detect and Remove PC Threats
If you are concerned that malware or PC threats similar to JsonCookies may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.
Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.