Prometheus TDS, Cookie Reloaded, and TA866
Learn how cookie-gated filtering and shared routing fit into email-delivered malware chains.
In this lesson, you will learn to:
- Describe cookie- and state-based filtering.
- Place Prometheus TDS accurately in TA866 and TA584 chains.
Prometheus TDS, Cookie Reloaded, and TA866
Examines Prometheus/Cookie Reloaded as a named filtering layer in Proofpoint reporting and separates it from later campaign payloads and actor identity.
Cookie Reloaded describes a filtering relationship
Proofpoint uses Cookie Reloaded in connection with Prometheus TDS URLs that filter visitors before a payload stage. Cookies and prior state can help determine whether a visitor already passed through, arrived with the expected campaign context, or should receive a decoy. This reduces duplicate delivery and frustrates automated analysis.
Record set-cookie responses, cookie names and lifetimes, redirects, referrers, and whether the outcome changes in a clean authorized profile. Never copy victim tokens or session values into public reporting without examining whether they identify a person or campaign customer. The analytic value is the state transition and service relationship, not only the cookie string.
TA866 connects delivery, profiling, and malware
Proofpoint tracked TA866 campaigns using malicious email, 404 TDS or other filtering, JavaScript delivered by OneDrive or similar hosting, WasabiSeed, and Screenshotter. Later chains could deliver additional malware. The actor and tool choices evolved; the important model is a sequence of specialized stages rather than one monolithic payload.
When Prometheus or Cookie Reloaded appears in a chain, distinguish the email actor, filtering service, file host, first-stage script, reconnaissance malware, and later payload. Evidence for one relationship does not automatically attribute infrastructure at another stage. Compare timestamps, campaign identifiers, response behavior, file hashes, and endpoint execution before joining observations.
Why the older service still matters
A named service can disappear from a current campaign while its design lessons remain. State, traffic quality, customer separation, and short-lived destinations recur across many TDS ecosystems. Detection should therefore describe navigation and endpoint behavior in addition to platform fingerprints.
Use historical names only with dated context. If a 2026 investigation finds a cookie gate, do not label it Prometheus merely because the mechanism looks similar. Seek distinctive infrastructure, response patterns, trusted reporting, or other corroboration. Technique similarity supports a hypothesis; it does not assign a service name.
Resources
- Proofpoint: TA584 Evolution — Revisit the dated role of Cookie Reloaded or Prometheus TDS before TA584’s 2025 preference for 404 TDS.