Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SquirrelWaffle

144
Global rank
149 infographic chevron month
Month rank
144 infographic chevron week
Week rank

SquirrelWaffle is a dropper that distributes Qbot and Cobalt Strike, in addition to other malware families. It leverages malicious documents that are part of compromised emails to drop second-level payloads to affected devices.

Dropper
Type
Unknown
Origin
8 September, 2021
First seen
2 September, 2026
Last seen

How to analyze SquirrelWaffle with ANY.RUN

Dropper
Type
Unknown
Origin
8 September, 2021
First seen
2 September, 2026
Last seen

IOCs

IP addresses
40.126.32.76
48.209.138.189
48.209.133.15
88.221.169.205
48.209.138.168
170.10.164.113
172.211.123.250
48.192.1.65
48.192.1.64
57.153.246.3
92.123.104.59
48.209.6.48
135.232.92.97
41.185.8.155
20.190.160.5
23.52.181.212
135.232.92.137
92.123.104.21
2.16.241.19
40.126.31.67
Hashes
ba348cddc24758ed8bbf477af2797b44e49c21838e945bc71ac9abc18b917838
efb3f5bf5e22b9831245c9adff23ef0e4e5373b764fbb52384a48d6360e1f1ff
5af1e50e65565c5c09c3cb7baff45cd6aee60ea0d5a5d00a9a9bb04135d17732
f20069001b2d11c3ee06e960c3397361bcf621f8259ec289dcb40311f8960fae
9a1048794bae37b54b4322e51367d67e0054bf82a2d2731d497920f481865d07
b7b43c340dbb6539a9ba9731002acdc271b13b2071e7f6fa23a48021f4fd4012
01255669e27b8559653e6979dfdeeb94b73fcc6936600a659f5642712a29f242
d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167
5726fc5495c432de5bd2020347e97867906ef267f3ff70f64989917b735e0b08
0653b7d2a5f98c7bae3e521048178de2aa22f41d457925f6478ffdc85bb94b65
a0355181e47dafef99636e8bdd2c2f2c2744f675f575a6f7b509c84e8e0d3f17
30a3156022450bfc52e07ab8209e81801d7a120262a9402b3a708ab63a5f6997
92f00a3e07d817aeb63c696c51b1de0d17c750cc6f0393cf0b6cb3033ccca55f
b717f6ccd0001c1651c4c46272dc53c00e749345a63b5474153e3e5e2b23c159
8402240870d295a7bc7461c2f9c7128a8fb156a719bbadc0d1877b3dff5bf2b6
d5292027db337041107639e23b38926bf05602974f97575bb982d09e81e5e4e4
01e9551caee7d60066e0dc215d064caf170e6fa96a189ac8e3365bcca705a3e1
8ec82d0d93f909267cae56a5d81e80f419eb7a91f77a9ccb006d310af7a99ba7
9aac746cd54aff6a961ba01acdd75fc1124f46837dba73ee7823122455043ed9
ee3920a7d69c74255c50eaad8b98cf01f3ba15a317ac668ff067aaa08052a0f5
Domains
google.com
activation-v2.sls.microsoft.com
client.wns.windows.com
self.events.data.microsoft.com
login.live.com
go.microsoft.com
settings-win.data.microsoft.com
alsader.net
www.bing.com
www.microsoft.com
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
sinaloworx.co.za
iconskw.com
ebookchuyennganh.com
avyanshglobal.com
giasuphire.tddvn.com
ocsp.digicert.com
priyacareers.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://alsader.net/bhdqaiq9rt/oqsadixzhtgtfjmcgypgenn5yn59cmv9f3tkfq==
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://sinaloworx.co.za/3gila8eo3r/oqsadixzhtgtfjmcgypgenn5yn59cmv9f3tkcw==
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/microsoft%20time-stamp%20pca%202010(1).crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.1.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.1.crl
http://sinaloworx.co.za/3gila8eo3r/oqsadixzhtgtfjmcgypgenn5yn59cmv9f3tkea==
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 3785
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 4251
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 5556
comments 0

What is SquirrelWaffle malware?

Discovered in September 2021, SquirrelWaffle is a loader/dropper malware strain designed to infect systems with malicious payloads. Security professionals speculate that it emerged as a replacement for Emotet after law enforcement dismantled the notorious botnet. It remains unclear whether the same group is responsible for this new threat, or if a different crew has stepped in to capitalize on the void left by the infamous malware.

The Squirrelwaffle payload, a PE DLL, is dropped on infected systems and executed using either rundll32.exe or regsvr32.exe, depending on the maldoc initiating the infection process. For instance, the payload can be executed using rundll32.exe with the following syntax: cmd.exe /c rundll32.exe C:\ProgramData[DLL FILENAME],ldr.

Primarily functioning as a malware loader, the DLL allows for deploying additional malware, with Qbot and Cobalt Strike installations often observed following the initial compromise. The DLL contains an IP blocklist in its configuration to further evade automated analysis platforms and security research organizations.

One of the the DLL's functionalities involves encoding and decoding information to enable communication between the victim system and the C2 infrastructure. The malware communicates with the C2 over HTTP POST requests containing obfuscated data, which is XOR-obfuscated and Base64-encoded.

The URL used for victim-C2 communication comprises a random alphanumeric string and the victim's IP address. The HTTP POST request body contains information about the victim system, such as %APPDATA% configuration, host name, username, and workstation configuration.

The C2 server responds with a status code and the previously sent beacon information obfuscated using the same method. This C2 channel can also deliver secondary payloads as per the attacker's discretion.

It is also worth noting that threat actors use compromised web servers, primarily running WordPress 5.8.1, for file distribution and deploy "antibot" scripts to avoid white-hat detection.

Analyzing SquirrelWaffle malware in ANY.RUN

ANY.RUN's cloud-based interactive sandbox facilitates seamless analysis of SquirrelWaffle samples for malware analysts. The platform efficiently compiles and displays execution data in accessible formats while gathering artifacts and Indicators of Compromise (IOCs) in real time.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Due to the specific traits inside its POST requests, SquirrelWaffle may be detected by network activity. On the screenshot below, loader was detected by a Suricata rule.

SquirrelWaffle’s network activity The SquirrelWaffle’s network activity with a detected loader

SquirrelWaffle malware execution

In order to be as inconspicuous as possible, Squirrelwaffle execution flow is simple. The loader often sneaks into the systems after a user opens a malicious document. Then the payload is downloaded, and it starts execution. While active, Squirrelwaffle connects to the Command & Control server to download the next-step payload.

Checked out a sample we've analyzed.

SquirrelWaffle’s malware configuration Malware configuration extracted from SquirrelWaffle

SquirrelWaffle malware distribution

SquirrelWaffle is primarily delivered through malicious documents in phishing campaigns, often employing stolen reply-chain attacks for distribution. This method involves hijacking an existing account to send phishing emails, rather than fabricating an account or creating a new one.

This technique boasts a high success rate, as it is challenging to defend against. By gaining access to email history, adversaries can craft convincing messages and continue existing conversation. This leaves few discernible phishing indicators. Researchers note that SquirrelWaffle-distributing emails are well-composed, and the attackers adeptly mimic the style of prior correspondence, regardless of the language.

While the malware predominantly targets English-speaking users, campaigns in French, German, Dutch, and Polish have also been detected — though they account for less than 30% of the total volume at the time of writing.

The malicious emails typically contain hyperlinks to infected ZIP archives hosted on attacker-controlled servers. These emails usually include a malicious .doc or .xls attachment, which triggers the execution of malware-retrieving code when opened.

The attackers fake the DocuSign signing platform, persuading recipients to enable macros in their MS Office suite. The embedded code employs string reversal for obfuscation, creates a VBS script in %PROGRAMDATA%, and then executes it.

This process retrieves Squirrelwaffle from one of five hardcoded URLs and delivers it as a DLL file to the compromised system. Subsequently, the Squirrelwaffle loader deploys malware such as Qakbot or the often-misused penetration testing tool, Cobalt Strike.

Conclusion

In the wake of Emotet's disruption, it was inevitable that threat actors would devise a substitute. It may be premature to declare SquirrelWaffle as the definitive replacement, but it possesses the fundamental attributes needed to potentially become the next prominent dropper and assume Emotet's role.

We recommend that organizations and researchers examine the TTPs (tactics, techniques, and procedures) utilized by this malware operation while it is still in the (relatively) early stages of gaining traction.

HAVE A LOOK AT

Rootkit screenshot
Rootkit
rootkit bootkit
A rootkit is a type of malicious software designed to provide unauthorized administrative-level access to a computer or network while concealing its presence. Rootkits are tools used by cybercriminals to hide their activities, including keyloggers, spyware, and other malware, often enabling long-term system exploitation.
Read More
Caminho Loader screenshot
Caminho Loader
caminho caminholoader
Caminho Loader is a Brazilian-origin Loader-as-a-Service operation that uses steganography to conceal .NET payloads within image files hosted on legitimate platforms. Active since March 2025, it has delivered a variety of malware and infostealers to victims within multiple industries across South America, Africa, and Eastern Europe.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More