SquirrelWaffle is a malware loader first observed in early to mid-September 2021 and has been used to deliver follow-on payloads including Cobalt Strike. It has been distributed through phishing emails, including spam emails carrying malicious Microsoft Office Word or Excel documents and phishing emails containing malicious URLs. The infection chain described in the content relies on user execution, particularly enabling malicious macros in Office attachments, after which VBS and PowerShell are used to stage execution and download the next component.
The malware’s dropper is described as a 32-bit DLL packed with a custom crypter/custom packer and loaded via rundll32 or regsvr32 depending on the initial maldoc vector. The dropper unpacks itself in memory using shellcode, XOR/ROR-based unpacking, and APLIB decompression. The unpacked SquirrelWaffle payload is also a 32-bit DLL with a single export named "ldr" and an internal DLL name of "Dll1.dll." Decoded configuration data has included a list of C2 URLs, may include C2 IPs, and contains the command "regsvr32.exe -s." The malware downloads a second-stage payload from C2 as a ".txt" file that is actually a disguised PE and loads it in memory. It also has execution capability via WinExec.
On infected hosts, SquirrelWaffle can collect host information including the computer name, current user name, and workstation configuration information; the content specifically notes collection of the user name from a compromised host. For command and control, it communicates using WS_32 socket APIs and has encoded communications to C2 servers using Base64. It has exfiltrated victim data using HTTP POST requests to its C2 servers. Anti-analysis behavior described in the content includes a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms.
The content also notes that previous campaigns leveraging SquirrelWaffle appeared aimed largely at email exfiltration. Microsoft reporting cited in the content states that DEV-0464, a QakBot distributor, has distributed SquirrelWaffle alongside other malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Meanwhile, DEV-0464 distributes the “TR” Qakbot and other malware such as SquirrelWaffle. | DEV-0464 also rapidly adopted the Microsoft Support Diagnostic Tool (MSDT) vulnerability (CVE-2022-30190) in their campaigns.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Meanwhile, DEV-0464 distributes the “TR” Qakbot and other malware such as SquirrelWaffle.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
In terms of the initial attack vector, the malware is being delivered by classic phishing documents and continues with dropping .vbs files and launching Powershell.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
Multiple actors and malware families are described as being delivered via spearphishing/phishing emails containing malicious links (e.g., APT28 used URL shorteners to redirect to credential harvesting sites; APT29 used links to ZIP files; APT33 used links to .hta files; BlackTech used links to cloud services; Wizard Spider used links to Google Drive/free file hosting).
the malware is being delivered by classic phishing documents and continues with dropping .vbs files and launching Powershell.
the malware is being delivered by classic phishing documents and continues with dropping .vbs files and launching Powershell.
The malware has execution capabilities using the WinExec function.
the malware is being delivered by classic phishing documents and continues with dropping .vbs files
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The malware then attempts to get the machine’s user name using the GetUserNameW () function.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The communication is done using the classic WS_32 API calls. The malware first create a socket , send the data using send() and receive information from the C2 using recv() .
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader observed in prior campaigns alongside QakBot and Cobalt Strike, with activity described as focused on email exfiltration and enabling email replay attacks.
Loader malware distributed alongside Qakbot by DEV-0464; used to establish access and facilitate further payload delivery in campaigns that can lead to ransomware.
Malware distributed by DEV-0464 alongside Qakbot in campaigns that can lead to ransomware activity.
A newly emerged malware loader/downloader delivered via phishing documents, VBS, and PowerShell. It gathers host information, decrypts embedded configuration data including IPs and C2 domains, communicates over sockets, downloads payloads, and is observed delivering Cobalt Strike, storing the downloaded binary as a .txt file before execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.