Executive Summary
Squirrelwaffle is a Windows loader used in spam campaigns to deliver dangerous payloads like Cobalt Strike and QakBot. It stealthily downloads and installs these secondary threats, increasing the risk of credential theft and remote access compromise. The malware’s simple dropper design allows attackers to remain hidden while executing complex attacks behind a single malicious attachment.
Enhanced Description
Squirrelwaffle is a lightweight Windows loader first identified in September 2021 and has since been used extensively in spam‑driven phishing campaigns to deliver more sophisticated malware payloads. The loader acts as an initial dropper, typically arriving as part of malicious email attachments or compromised websites and is designed to remain stealthy while it pulls in secondary threats from remote servers. Once executed, Squirrelwaffle downloads and deploys additional tools such as the Cobalt Strike beacon and the QakBot banking trojan, thereby expanding its foothold within targeted systems. The malware’s primary function is to stage these secondary payloads by establishing outbound HTTP/HTTPS connections to command-and-control (C&C) infrastructure. By doing so, it reduces the likelihood of sandbox analysis catching the more dangerous components early in the attack chain. In addition to downloading, Squirrelwaffle can launch executables from memory or disk without leaving obvious execution traces, making traditional signature‑based detection methods less effective. Operators using Squirrelwaffe typically combine it with social engineering tactics, embedding links or attachments that mimic legitimate documents. Once a user activates the attachment, the loader silently establishes persistence through scheduled tasks or registry run keys, then proceeds to install downstream malware that can exfiltrate credentials, compromise banking accounts, and establish command‑and‑control backdoors.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate: the data provided confirms Squirrelwaffe’s role as a loader in spam campaigns delivering known payloads, but there is limited publicly available technical analysis of its internals. Further research is needed on persistence mechanisms, file‑system changes, and command structures to fully assess its capabilities.
Squirrelwaffle is a loader that was first seen in September 2021. It has been used in spam email campaigns to deliver additional malware such as Cobalt Strike and the QakBot banking trojan.(Citation: ZScaler Squirrelwaffle Sep 2021)(Citation: Netskope Squirrelwaffle Oct 2021)