SquirrelWaffle was used in phishing campaigns that delivered malicious ZIP archives containing Word or Excel documents, then relied on VBA or XLM macros to launch a multi-stage infection chain. In documented cases, the documents dropped a VBS script or invoked PowerShell to download DLL payloads, which were executed with rundll32 or regsvr32 and ultimately fetched follow-on malware including Cobalt Strike and, in some campaigns, Qakbot. Traffic analysis of one observed intrusion showed the loader arriving from an email-delivered ZIP file, infecting a Windows host, and then transitioning into Cobalt Strike activity on the network.
Reverse-engineering reports show the SquirrelWaffle DLL loader used a custom packer and several anti-analysis measures, including manual rebasing, junk API padding, in-memory decryption, and remapping of a second-stage PE into the current process. The main loader decoded hardcoded C2 URLs, collected host data such as computer name, username, domain, local IP address, and APPDATA path, and sent that information in HTTP POST requests before acting on server responses. Depending on the returned tasking, it could drop and register executables, run payloads from TEMP, execute shellcode through a threadpool wait callback, or write and launch an operator-specified executable path.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 20 September 2021, researchers observed a new Squirrelwaffle variant using malicious Excel documents instead of Word documents. This variant used XLM macros, downloaded masqueraded DLL payloads from C2 servers, and executed them via regsvr32.
On 2021-09-17, a malware infection involving the Squirrelwaffle loader followed by Cobalt Strike was documented. The incident involved a malicious ZIP archive delivered by email, a Word document, host artifacts, and captured network traffic showing when Cobalt Strike activity began.
Researchers first saw Squirrelwaffle during malicious spam campaigns at the start of September 2021. The malware was identified as an email-delivered loader distributed through phishing links to ZIP archives containing weaponized Office documents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cynet.com
Open sourcemalware-traffic-analysis.net
Open source0ffset.net
Open source0ffset.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.