Cyber Threat Actor: Cookies
| Actor Type | Location | Known Incidents |
Sensationalist
|
Nepal
|
1 incident |
|---|
Profile
The threat actor is known by the alias Cookies called Captain Smoker 3R, which appears in open‑source references as a combined moniker. Separate reporting also references the actor simply as Cookies. Another identifier used by the same individual or group is Captain Smoker 3R. Open‑source indications place the actor’s geographic base in Nepal. On 5 July 2024 the actor gained unauthorized access to the website of the Office of the Chief Minister and Council of Ministers in Sudurpaschim Province. The intrusion was manifested as a defacement page that displayed a message claiming responsibility for the breach. Within that message the actor explicitly identified themselves as Captain Smoker 3R.
Following the defacement, the provincial administration notified Kathmandu's Department of Information Technology about the incident. The Office of the Chief Minister and Council of Ministers then commenced recovery procedures to restore the compromised portal. Despite those remedial actions, the website remained unavailable to users on the day after the attack. No further operational disturbances were reported by the provincial office beyond the initial defacement. Investigators also found no evidence of data exfiltration or additional compromise linked to the incident. The incident was covered by New Business Age, which published an article detailing the defacement and the official response. The article can be accessed at https://www.newbusinessage.com/articles/view/21451/ for readers seeking the original source.
