logo

The Squirrelwaffle: New Loader Delivers Cobalt Strikes

ID: 354abd78-32b9-5c90-b684-4a7838526bf3

STIX ID: report--354abd78-32b9-5c90-b684-4a7838526bf3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz analyzed an active Squirrelwaffle loader campaign (since mid‑September 2021) that uses email thread hijacking and malicious Word/Excel documents with macros to drop VBS/PowerShell stagers which fetch a packed DLL executed via rundll32/regsvr32; the loader contains XOR‑obfuscated C2 configuration, communicates using Base64+XOR over HTTP(S), can fetch a second‑stage executable that unpacks a Cobalt Strike stager/beacon, and the report provides extensive IOCs (URLs, domains, IPs, and MD5 hashes) and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.