logo

Top attack vectors: November 2021

ID: 431a73f9-9224-5dd5-9c79-69b9ba8e66a8

STIX ID: report--431a73f9-9224-5dd5-9c79-69b9ba8e66a8

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2021-12-14

Date Updated: 2026-04-27

Author: Kyle Pellett

...
...

**November 2021 SOC monthly report:** The SOC observed a 10% rise in commodity malware incidents driven by phishing emails linking to macro-enabled Office documents—SquirrelWaffle accounted for ~25% of commodity malware attempts and commonly delivered Qakbot or CobaltStrike—and ongoing cryptojacking operations (XMRig, TNT Worm, and malicious npm packages) exploiting exposed cloud resources; the report provides detection rules (e.g., monitor Excel -> regsvr32 activity, network traffic to mining pools) and mitigation advice (disable macros, patch public-facing servers, secure S3 and cloud credentials).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.