Squirrelwaffle
MITRE ATT&CK: S1030 View on attack.mitre.org
Aliases: DatopLoader, Squirrelwaffle
- First seen
- 2021-09-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 31 (7 malicious)
- Last IoC activity
- 2026-08-10 04:56:58
- Profile updated
- 2026-07-07 13:45:26
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
Squirrelwaffle is a loader that was first seen in September 2021. It has been used in spam email campaigns to deliver additional malware such as Cobalt Strike and the QakBot banking trojan.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to Squirrelwaffle (S1030). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 1ff17ce907ce2d98867ec9c78998518e.dll | 2026-04-27 | 1 |
| file sample | e8f3bcb2560827a8aee38e739fe927af.dll | 2026-04-23 | 1 |
| file sample | test.test | 2026-04-22 | 1 |
| file sample | 6484d8ffd4a6de7947534571e9907b4e.dll | 2026-04-22 | 1 |
| file sample | sample.doc.vir | 2026-03-25 | 1 |
| file sample | 0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e.dll | 2026-03-03 | 1 |
| file sample | d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll | 2025-04-25 | 2 |
Detection coverage
- 4 YARA rules
- 517 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- System Information Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Spearphishing Link (attack-pattern)
- Regsvr32 (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Malicious Link (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Standard Encoding (attack-pattern)
- Web Protocols (attack-pattern)
- Malicious File (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Software Packing (attack-pattern)
- Archive via Custom Method (attack-pattern)
- PowerShell (attack-pattern)
- Windows Command Shell (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Rundll32 (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Detection rules
- MALPEDIA_Win_Squirrelwaffle_Auto (yara-rule)
- SEKOIA_Loader_Win_Squirrelwaffle (yara-rule)
- SEKOIA_Loader_Win_Squirrelwaffle_Doc (yara-rule)
- CAPE_Squirrelwaffle (yara-rule)
Reports & references
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- redcanary.com — Intelligence Insights November 2021 (report)
- zscaler.com — Squirrelwaffle New Loader Delivering Cobalt Strike (report)
- github.com — 2021 10 02%20 %20Squirrelwaffle%20 %20From%20Maldoc%20To%20Cobalt%20Strike (report)
- 0ffset.net — Squirrelwaffle Custom Packer (report)
- 0ffset.net — Squirrelwaffle Main Loader (report)
- malware-traffic-analysis.net — Index (report)
- cybereason.com — Threat Analysis Report Datoploader Exploits Proxyshell To Deliver Qbot And Cobalt Strike (report)
- redcanary.com — Intelligence Insights December 2021 (report)
- cynet.com — Understanding Squirrelwaffle (report)
- netskope.com — Squirrelwaffle New Malware Loader Delivering Cobalt Strike And Qakbot (report)
- elis531989.medium.com — The Squirrel Strikes Back Analysis Of The Newly Emerged Cobalt Strike Loader Squirrelwaffle 937B73Dbd9F9 (report)
- Trend Micro — Squirrelwaffle Exploits Proxyshell And Proxylogon To Hijack Email Chains (report)
- Cisco Talos — Squirrelwaffle Emerges (report)
- twitter.com — 1464268732096815105 (report)
- blog.minerva-labs.com — A New Datoploader Delivers Qakbot Trojan (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Squirrelwaffle (report)
- McAfee — The Newest Malicious Actor Squirrelwaffle Malicious Doc (report)
- news.sophos.com — Vulnerable Exchange Server Hit By Squirrelwaffle And Financial Fraud (report)
- sentinelone.com — Is Squirrelwaffle The New Emotet How To Detect The Latest Malspam Loader (report)
- youtube.com — Watch (report)
- twitter.com — 1442496131410190339 (report)
- certitude.consulting — Unpatched Exchange Servers Distribute Phishing Links Squirrelwaffle (report)
- security-soup.net — Squirrelwaffle Maldoc Analysis (report)
- blogs.blackberry.com — Threat Thursday Squirrelwaffle Loader (report)