Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
LevelBlue Labs recently discovered a new highly evasive loader that is being delivered to specific targets through phishing attachments.
The observed SquidLoader attack follows a five-stage infection chain: Spear-phishing email: The attack commences with a targeted spear-phishing email directed at employees of Hong Kong financial services institutions. Password-Protected RAR archive: The email contains an attachment disguised as an invoice within a password-protected RAR archive.
The analyzed sample exhibits significant control flow obfuscation... This technique makes static analysis and reverse engineering significantly more challenging by introducing numerous conditional jumps and loops that obscure the actual program flow.
SquidLoader employs sophisticated techniques to dynamically resolve necessary Windows APIs... The names of these APIs are individually XORed and then immediately overwritten in memory, effectively erasing any static traces of the API names.
This binary is crafted with an icon and name mimicking a Microsoft Word document to deceive the user. However, the underlying file properties resemble a legitimate "AMDRSServ.exe" (Radeon settings host service), further aiding in social engineering.
The shellcode that is delivered is also loaded in the same loader process, likely to avoid writing the payload to disk and thus risk being detected.
Each byte is XORed with the value 0xF4 and then has 19 added to it. This de-obfuscation routine reveals the subsequent stages of the malware.
The malware hijacks the __scrt_common_main_seh function during its epilogue, diverting control to the malicious code before WinMain is ever reached.
SquidLoader incorporates a comprehensive suite of anti-analysis measures to evade detection... Username check... checks if it matches "Abby" or "WALKER," common usernames in some sandbox environments.
SquidLoader uses a syscall to NtQuerySystemInformation with the SystemProcessInformation parameter to obtain a list of running processes.
The malware transmits a significant amount of information about the compromised host to the C2 server, including: IP address Username Computer name Windows version Process ID Thread ID Filename Administrator privileges status Active Code Page OEM Code Page
SquidLoader incorporates a comprehensive suite of anti-analysis measures to evade detection... Username check... checks if it matches "Abby" or "WALKER," common usernames in some sandbox environments.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated malware loader used in spear-phishing campaigns against financial institutions. It uses multi-stage execution, dynamic API resolution, heavy string/control-flow obfuscation, anti-analysis/anti-sandbox/anti-debugging checks, then contacts C2 and downloads and executes an in-memory Cobalt Strike Beacon.
Loader malware observed in attacks against Hong Kong financial institutions (per Trellix).
A highly evasive loader delivered via phishing attachments that downloads encrypted shellcode over HTTPS, executes it in-memory, and uses extensive anti-analysis, anti-debugging, obfuscation, and direct-syscall techniques to evade detection while delivering second-stage payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.