Sunday, April 27, 2025
HomeAndroidThreat Actors Using Squirrelwaffle Loader to Deploy Qakbot & Cobalt Strike Malware

Threat Actors Using Squirrelwaffle Loader to Deploy Qakbot & Cobalt Strike Malware

Published on

SIEM as a Service

Follow Us on Google News

A new threat emerged recently in the wild that drops malware like Qakbot and Cobalt Strike onto negotiated systems and networks; this new threat is dubbed as “Squirrelwaffle” and threat actors are actively spreading Squirrelwaffle through several malicious email campaigns.

Shortly after the disruption of the widely used botnet, Emotet by the law enforcement agencies, Squirrelwaffle emerged as an alternative to Emotet. The first signs of this new threat appeared in September 2021, and the distribution volumes reached a peak at the end of that month.

Email Campaigns & Languages Used

In addition to stolen reply-chain email campaigns in English, but, the spammers also use emails in the following languages:-

- Advertisement - Google News
  • French
  • German
  • Dutch
  • Polish

According to the report “A malicious .doc or .xls attachment is typically attached to an email that links to malicious ZIP archives hosted on attacker-controlled web servers and runs malware retrieval code on opening.”

In order to trick recipients into enabling the macros within MS Office Suite, threat actors use DocuSign as bait.

Attack process

As part of the attack, string reversal is used to obfuscate the code, which then writes a VBS script to the %PROGRAMDATA% directory, and then executes it.

Once done, after that from one of the five hardcoded URLs, it fetches Squirrelwaffle in DLL form to deliver it onto the endangered system. Now, here, at this point, if the Squirrelwaffle in DLL form is successfully delivered onto the victim’s system, then using rundll32.exe the malicious DLL is executed.

After completing all the stages, the Squirrelwaffle loader deploys malware like Qakbot and Cobalt Strike. For post-exploitation tasks after deploying beacons, the threat actors use the cracked versions of Cobalt Strike to gain access to compromised devices remotely.

With a C2 over HTTP POST requests containing obfuscated data, the malware tries to communicate, and the body of the HTTP POST request includes the following information about the victim system:-

  • %APPDATA% configuration.
  • The hostname of the system.
  • The username of the victim.
  • The Workstation configuration of the system.

Moreover, it is possible that Squirrelwaffle is a revamped version of Emotet by the members who escaped the law enforcement; or it may be a new attempt by other threat actors who are trying the fill the void left behind by Emotet.

So, the experts of Cisco Talos have urged all the security professionals and organizations to stay aware of the new TTPs used by the threat actors.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Gamers Beware! New Attack Targets Gamers to Deploy AgeoStealer Malware

The cybersecurity landscape faces an escalating crisis as AgeoStealer joins the ranks of advanced...

Compliance And Governance: What Every CISO Needs To Know About Data Protection Regulations

The cybersecurity landscape has changed dramatically in recent years, largely due to the introduction...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Gamers Beware! New Attack Targets Gamers to Deploy AgeoStealer Malware

The cybersecurity landscape faces an escalating crisis as AgeoStealer joins the ranks of advanced...