Squirrelwaffle

MITRE ATT&CK: S1030 View on attack.mitre.org

Aliases: DatopLoader, Squirrelwaffle

First seen
2021-09-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Related IoCs
31 (7 malicious)
Last IoC activity
2026-08-10 04:56:58
Profile updated
2026-07-07 13:45:26

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

Squirrelwaffle is a loader that was first seen in September 2021. It has been used in spam email campaigns to deliver additional malware such as Cobalt Strike and the QakBot banking trojan.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to Squirrelwaffle (S1030). The 7 most recently updated:

TypeIndicatorUpdatedSources
file sample 1ff17ce907ce2d98867ec9c78998518e.dll 2026-04-27 1
file sample e8f3bcb2560827a8aee38e739fe927af.dll 2026-04-23 1
file sample test.test 2026-04-22 1
file sample 6484d8ffd4a6de7947534571e9907b4e.dll 2026-04-22 1
file sample sample.doc.vir 2026-03-25 1
file sample 0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e.dll 2026-03-03 1
file sample d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll 2025-04-25 2

Detection coverage

  • 4 YARA rules
  • 517 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Visual Basic (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Malicious Link (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Web Protocols (attack-pattern)
  • Malicious File (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Software Packing (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Rundll32 (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Detection rules

  • MALPEDIA_Win_Squirrelwaffle_Auto (yara-rule)
  • SEKOIA_Loader_Win_Squirrelwaffle (yara-rule)
  • SEKOIA_Loader_Win_Squirrelwaffle_Doc (yara-rule)
  • CAPE_Squirrelwaffle (yara-rule)

Reports & references

  • Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
  • redcanary.com — Intelligence Insights November 2021 (report)
  • zscaler.com — Squirrelwaffle New Loader Delivering Cobalt Strike (report)
  • github.com — 2021 10 02%20 %20Squirrelwaffle%20 %20From%20Maldoc%20To%20Cobalt%20Strike (report)
  • 0ffset.net — Squirrelwaffle Custom Packer (report)
  • 0ffset.net — Squirrelwaffle Main Loader (report)
  • malware-traffic-analysis.net — Index (report)
  • cybereason.com — Threat Analysis Report Datoploader Exploits Proxyshell To Deliver Qbot And Cobalt Strike (report)
  • redcanary.com — Intelligence Insights December 2021 (report)
  • cynet.com — Understanding Squirrelwaffle (report)
  • netskope.com — Squirrelwaffle New Malware Loader Delivering Cobalt Strike And Qakbot (report)
  • elis531989.medium.com — The Squirrel Strikes Back Analysis Of The Newly Emerged Cobalt Strike Loader Squirrelwaffle 937B73Dbd9F9 (report)
  • Trend Micro — Squirrelwaffle Exploits Proxyshell And Proxylogon To Hijack Email Chains (report)
  • Cisco Talos — Squirrelwaffle Emerges (report)
  • twitter.com — 1464268732096815105 (report)
  • blog.minerva-labs.com — A New Datoploader Delivers Qakbot Trojan (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Squirrelwaffle (report)
  • McAfee — The Newest Malicious Actor Squirrelwaffle Malicious Doc (report)
  • news.sophos.com — Vulnerable Exchange Server Hit By Squirrelwaffle And Financial Fraud (report)
  • sentinelone.com — Is Squirrelwaffle The New Emotet How To Detect The Latest Malspam Loader (report)
  • youtube.com — Watch (report)
  • twitter.com — 1442496131410190339 (report)
  • certitude.consulting — Unpatched Exchange Servers Distribute Phishing Links Squirrelwaffle (report)
  • security-soup.net — Squirrelwaffle Maldoc Analysis (report)
  • blogs.blackberry.com — Threat Thursday Squirrelwaffle Loader (report)

External references