logo

Experts Uncover New Evasive SquidLoader Malware Targeting Chinese Organizations

ID: d2524c55-2a19-56d2-b2bd-b97e82d93342

STIX ID: report--d2524c55-2a19-56d2-b2bd-b97e82d93342

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-20

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

AT&T LevelBlue Labs discovered SquidLoader, an evasive malware loader observed in April 2024 that spreads through phishing attachments disguised as Word binaries and fetches in-memory second-stage shellcode (including Cobalt Strike). The loader uses multiple anti-analysis and evasion techniques—encrypted code segments, unused/dead code, control-flow obfuscation, debugger detection, and direct syscalls—to avoid detection and hinder analysis; the report also references related loader families (Taurus Loader, PikaBot, Latrodectus) and recent infrastructure disruptions by law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.