Researchers detailed two malware loaders used to establish initial access and stage follow-on intrusions: SquirrelWaffle, which arrived through phishing documents and dropped VBS and PowerShell components before retrieving a packed 32-bit DLL, and Bumblebee, which was delivered through compromised open-source tools in an MSI installer containing a CAB archive. In the SquirrelWaffle chain, the DLL dropper unpacked shellcode using XOR/ROR logic and APLIB decompression, then loaded a payload exported as ldr that collected host data, decrypted embedded configuration, and extracted command-and-control IP addresses and domains. The malware communicated over standard WS_32 socket APIs and downloaded Cobalt Strike, saving the binary with a .txt extension before execution.
Analysis of Bumblebee showed a different but similarly stealthy execution path built around DLL sideloading and DLL proxy forwarding. The installer abused the legitimate Microsoft-signed icardagt.exe binary to load a malicious DLL that was renamed to version.dll at runtime, while anti-analysis features included junk code, timing checks, and possible virtual-machine detection through WMI queries. Investigators also observed failed file-creation attempts, a network connection to 19ak90ckxyjxc.life, a temporary installation directory, and a Windows Installer UserData registry artifact, reinforcing that the MSI package orchestrated the full infection chain and positioned the malware for later hands-on-keyboard activity or ransomware deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2025-06-15, a malware analysis described a Bumblebee sample delivered through compromised open source tools via an MSI installer. The report documented DLL sideloading and proxy forwarding using the legitimate Microsoft-signed icardagt.exe binary, along with anti-analysis behavior and a connection to 19ak90ckxyjxc.life.
On 2021-09-21, a technical analysis detailed SquirrelWaffle's custom crypter, shellcode-based unpacking, configuration decryption, and C2 extraction. The report also noted similarities to crypters seen in Ursnif, Zloader, and Hancitor and warned of its potential role in later ransomware intrusions.
The SquirrelWaffle malware loader was first observed in early to mid-September 2021 delivering the Cobalt Strike framework. The analysis describes a phishing-based infection chain that drops VBS and PowerShell components before downloading the loader DLL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.