SquirrelWaffle was used in phishing campaigns that delivered malicious ZIP archives containing Word or Excel documents, then relied on VBA or XLM macros to launch a multi-stage infection chain. In documented cases, the documents dropped a VBS script or invoked PowerShell to download DLL payloads, which were executed with rundll32 or regsvr32 and ultimately fetched follow-on malware including Cobalt Strike and, in some campaigns, Qakbot. Traffic analysis of one observed intrusion showed the loader arriving from an email-delivered ZIP file, infecting a Windows host, and then transitioning into Cobalt Strike activity on the network.
Reverse-engineering reports show the SquirrelWaffle DLL loader used a custom packer and several anti-analysis measures, including manual rebasing, junk API padding, in-memory decryption, and remapping of a second-stage PE into the current process. The main loader decoded hardcoded C2 URLs, collected host data such as computer name, username, domain, local IP address, and APPDATA path, and sent that information in HTTP POST requests before acting on server responses. Depending on the returned tasking, it could drop and register executables, run payloads from TEMP, execute shellcode through a threadpool wait callback, or write and launch an operator-specified executable path.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
On 20 September 2021, researchers observed a new Squirrelwaffle variant using malicious Excel documents instead of Word documents. This variant used XLM macros, downloaded masqueraded DLL payloads from C2 servers, and executed them via regsvr32.
On 2021-09-17, a malware infection involving the Squirrelwaffle loader followed by Cobalt Strike was documented. The incident involved a malicious ZIP archive delivered by email, a Word document, host artifacts, and captured network traffic showing when Cobalt Strike activity began.
Researchers first saw Squirrelwaffle during malicious spam campaigns at the start of September 2021. The malware was identified as an email-delivered loader distributed through phishing links to ZIP archives containing weaponized Office documents.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 72 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cynet.com
Open sourcemalware-traffic-analysis.net
Open source0ffset.net
Open source0ffset.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.