The Newest Malicious Actor: “Squirrelwaffle” Malicious Doc.
ID: 31414142-09cf-5f6e-bc2d-85b94bb5512c
STIX ID: report--31414142-09cf-5f6e-bc2d-85b94bb5512c
Feed Name: McAfee Labs Blog
This McAfee blog analyzes the SquirrelWaffle malicious Office document campaign observed from September 2021, describing a phishing-delivered ZIP containing a macro-enabled Word doc that drops an obfuscated VBS; the VBS downloads DLL payloads to C:\ProgramData and executes them via rundll32 (export function 'ldr'), resulting in Cobalt Strike deployment. The report maps techniques to MITRE ATT&CK, provides sample hashes and download URLs, and shows the document’s VBA/UserForm-based code and execution chain used to trick users into enabling macros.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
