ATT&CKReferencesNetskope Squirrelwaffle Oct 2021

Netskope Squirrelwaffle Oct 2021

Palazolo, G. (2021, October 7). SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot. Retrieved August 9, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareSquirrelwaffle

Squirrelwaffle has been packed with a custom packer to hide payloads.

T1027.013
Encrypted/Encoded File
MalwareSquirrelwaffle

Squirrelwaffle has been obfuscated with a XOR-based algorithm.

T1059.001
PowerShell
MalwareSquirrelwaffle

Squirrelwaffle has used PowerShell to execute its payload.

T1059.003
Windows Command Shell
MalwareSquirrelwaffle

Squirrelwaffle has used `cmd.exe` for execution.

T1059.005
Visual Basic
MalwareSquirrelwaffle

Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine.

T1105
Ingress Tool Transfer
MalwareSquirrelwaffle

Squirrelwaffle has downloaded and executed additional encoded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareSquirrelwaffle

Squirrelwaffle has decrypted files and payloads using a XOR-based algorithm.

T1204.002
Malicious File
MalwareSquirrelwaffle

Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments.

T1218.011
Rundll32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `rundll32.exe`.

T1497
Virtualization/Sandbox Evasion
MalwareSquirrelwaffle

Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms.

T1566.001
Spearphishing Attachment
MalwareSquirrelwaffle

Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.