Squirrelwaffle is a modular malware loader first documented by researchers at Proofpoint and Cisco Talos in September 2021. It operates as a downloader for secondary payloads, often delivering Cobalt Strike beacons, Qbot (QakBot), or ransomware families such as BlackByte and BlackCat. The malware is believed to be operated by a financially motivated threat cluster that leverages compromised email threads to distribute malicious attachments.
Squirrelwaffle propagates primarily through phishing emails that reply to existing conversation threads, a technique known as "thread hijacking." The initial infection vector is a malicious Microsoft Office document containing obfuscated VBA macros that, when enabled, download the Squirrelwaffle DLL payload from an attacker-controlled server. The loader uses a custom packer and checks for debugger presence and sandbox environments. For command-and-control (C2), Squirrelwaffle employs HTTP POST requests to hardcoded IP addresses or domains, with traffic disguised as standard web communication. Persistence is achieved by creating a scheduled task or a registry Run key that points to the dropped DLL. Evasion includes API unhooking by overwriting ntdll functions detected by user-land hooks, and the malware avoids execution on systems with certain languages or region settings common in security research environments.
First observed in active campaigns in late August 2021, Squirrelwaffle was tied to large-scale phishing waves targeting North American and European organizations in the finance, insurance, and manufacturing sectors. One notable incident in October 2021 saw the loader deliver Cobalt Strike beacons that led to BlackByte ransomware deployment against a critical infrastructure entity. No CVEs are directly attributed to Squirrelwaffle, as it relies on social engineering and macro execution rather than exploiting software vulnerabilities. Law enforcement actions have not been publicly associated with this specific malware family as of 2024.
Squirrelwaffle payloads have been associated with file hashes such as SHA-256 c5c3e7b4a1f2d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 (example from Proofpoint report). Network indicators include C2 domains mimicking legitimate services (e.g., update-bing[.]com) and User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36. Behavioral signatures involve macro execution that reads from a decoded base64 payload, and the loader performing a URL check to a remote server before dropping the secondary payload.
Squirrelwaffle acts as a gateway for ransomware and data theft, enabling attackers to exfiltrate sensitive data and deploy encryption across networks. Infected organizations have suffered operational downtime and financial losses, with ransom demands averaging $100,000–$500,000. The primary targets are mid-to-large enterprises in the financial and manufacturing sectors, though any organization with active email threads is at risk.
Defenders should block Microsoft Office macros from the internet, implement email filtering to detect thread hijacking patterns, and deploy endpoint detection rules (e.g., SIGMA rules for scheduled task creation by rundll32.exe). Threat intelligence feeds from Proofpoint (www.proofpoint.com/us/threat-insight/post/squirrelwaffle-loader) and Cisco Talos provide updated IOCs. Regular user training on recognizing conversation hijacking in emails is strongly recommended.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.