The Squirrelwaffle: New Loader Delivers Cobalt Strikes
ID: 354abd78-32b9-5c90-b684-4a7838526bf3
STIX ID: report--354abd78-32b9-5c90-b684-4a7838526bf3
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz analyzed an active Squirrelwaffle loader campaign (since mid‑September 2021) that uses email thread hijacking and malicious Word/Excel documents with macros to drop VBS/PowerShell stagers which fetch a packed DLL executed via rundll32/regsvr32; the loader contains XOR‑obfuscated C2 configuration, communicates using Base64+XOR over HTTP(S), can fetch a second‑stage executable that unpacks a Cobalt Strike stager/beacon, and the report provides extensive IOCs (URLs, domains, IPs, and MD5 hashes) and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
