Monday, May 5, 2025
HomeCyber Security NewsVulnerable Exchange Server Hit by Squirrelwaffle Malware Loader

Vulnerable Exchange Server Hit by Squirrelwaffle Malware Loader

Published on

SIEM as a Service

Follow Us on Google News

Squirrelwaffle malware has been found in existence since the mid of September 2021. This malware is designed to cause chain infections. The Rapid Response Team at Sophos has recently discovered that the Squirrelwaffle malware loader used ProxyLogon and ProxyShell exploits for targeting Microsoft Exchange Server.

After gaining access to the vulnerable server, the attackers used the email thread hijacking technique which involves inserting malicious replies into Employees’ existing email threads to distribute the Squirrelwaffle malware to both internal and external recipients.

When they monitored further, they found that the vulnerable server was not only used for malicious spam campaigns but also for a financial fraud attack by extracting information from a stolen email thread.

- Advertisement - Google News

Squirrelwaffle

Squirrelwaffle is a type of malware loader distributed via spam campaigns as a malicious office document. This provides information about the victim’s environment and with a channel that can be used to deliver and infect with other malware. 

When a victim opens the malicious office document and enables macros, it downloads a VB script and executes Cobalt Strike Beacons which give control over the victim’s machine.

The Investigation

Usually, the Squirrelwaffle attack is ended when the defenders detect and remediate by providing patches to the vulnerable servers. But in the recent set of events, such remediation measures wouldn’t have stopped the financial fraud attack as they have already exported an email thread about customer payment from the victim’s exchange server. Hence it is recommended to investigate further for other impacts.

Typo-squatted domains were registered and used by the attackers for email thread replies.

The registered domain appears similar to the original victim’s domain but with a small typo that is often not noticed by the victims. Once they convince the victims, they use these email threads to redirect the payments.
Image

To provide additional legitimacy to the victims, they used additional email addresses from the typo-squatted domain and added them in CC of the reply emails. Just like every other phishing campaign, these attackers also provide a sense of urgency to the victims.

Prevention

It is advised to keep the Microsoft Exchange Servers updated and patched to prevent any type of compromise. Industry-recognized prevention methods such as SPF records, DKIM, and DMARC records must be standard to stop phishing campaigns. It is also necessary to provide knowledge to all the employees about Phishing attempts.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

North Korean Hacker Tries to Infiltrate Kraken Through Job Application

Leading cryptocurrency exchange Kraken has disclosed that it recently thwarted an infiltration attempt by...

Multiple Flaws in Tenda RX2 Pro Let Attackers Gain Admin Access

Security researchers have uncovered a series of critical vulnerabilities in the Tenda RX2 Pro...

Hackers Exploit Email Fields to Launch XSS and SSRF Attacks

Cybersecurity researchers are raising alarms as hackers increasingly weaponize email input fields to execute cross-site...

Luna Moth Hackers Use Fake Helpdesk Domains to Target Victims

A recent investigation by cybersecurity firm EclecticIQ, in collaboration with threat hunters, has exposed...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

North Korean Hacker Tries to Infiltrate Kraken Through Job Application

Leading cryptocurrency exchange Kraken has disclosed that it recently thwarted an infiltration attempt by...

Multiple Flaws in Tenda RX2 Pro Let Attackers Gain Admin Access

Security researchers have uncovered a series of critical vulnerabilities in the Tenda RX2 Pro...

Hackers Exploit Email Fields to Launch XSS and SSRF Attacks

Cybersecurity researchers are raising alarms as hackers increasingly weaponize email input fields to execute cross-site...