ATT&CKSoftwareSquirrelwaffle

Squirrelwaffle

S1030

Malware.View on attack.mitre.org

About this malware

Squirrelwaffle is a loader that was first seen in September 2021. It has been used in spam email campaigns to deliver additional malware such as Cobalt Strike and the QakBot banking trojan.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1016
System Network Configuration Discovery

Squirrelwaffle has collected the victim’s external IP address.

T1027.002
Software Packing

Squirrelwaffle has been packed with a custom packer to hide payloads.

T1027.013
Encrypted/Encoded File

Squirrelwaffle has been obfuscated with a XOR-based algorithm.

T1033
System Owner/User Discovery

Squirrelwaffle can collect the user name from a compromised host.

T1041
Exfiltration Over C2 Channel

Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers.

T1059.001
PowerShell

Squirrelwaffle has used PowerShell to execute its payload.

T1059.003
Windows Command Shell

Squirrelwaffle has used `cmd.exe` for execution.

T1059.005
Visual Basic

Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine.

T1071.001
Web Protocols

Squirrelwaffle has used HTTP POST requests for C2 communications.

T1082
System Information Discovery

Squirrelwaffle has gathered victim computer information and configurations.

T1105
Ingress Tool Transfer

Squirrelwaffle has downloaded and executed additional encoded payloads.

T1132.001
Standard Encoding

Squirrelwaffle has encoded its communications to C2 servers using Base64.

T1140
Deobfuscate/Decode Files or Information

Squirrelwaffle has decrypted files and payloads using a XOR-based algorithm.

T1204.001
Malicious Link

Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns.

T1204.002
Malicious File

Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments.

View all 21 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Netskope Squirrelwaffle Oct 2021 Open source
    Palazolo, G. (2021, October 7). SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot. Retrieved August 9, 2022.
  2. ZScaler Squirrelwaffle Sep 2021 Open source
    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.