Threat Advisory

SquidLoader Malware Targeting Chinese Firms Through Phishing Attacks

Threat: Malware
Targeted Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have identified a new, highly evasive loader malware dubbed "SquidLoader." Delivered through phishing attachments, SquidLoader is used to load second-stage payloads such as modified Cobalt Strike samples, which are hardened against static analysis. The malware primarily targets Chinese-speaking victims and employs numerous decoy and evasion techniques to avoid detection and hinder analysis. Despite its initial focus on specific regions, the techniques used in SquidLoader could be replicated by other threat actors.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have identified a new, highly evasive loader malware dubbed "SquidLoader." Delivered through phishing attachments, SquidLoader is used to load second-stage payloads such as modified Cobalt Strike samples, which are hardened against static analysis. The malware primarily targets Chinese-speaking victims and employs numerous decoy and evasion techniques to avoid detection and hinder analysis. Despite its initial focus on specific regions, the techniques used in SquidLoader could be replicated by other threat actors.[emaillocker id="1283"]

SquidLoader masquerades as legitimate documents with descriptive filenames and Word document icons to lure victims. The malware uses a legitimate expired certificate to appear less suspicious and communicates with command and control (C&C) servers using self-signed certificates. Upon execution, SquidLoader duplicates itself to a predefined location and restarts from there without employing persistence mechanisms, leaving that task to the second-stage payload. The loader downloads and executes encrypted shellcode via a GET HTTPS request, using heavy obfuscation techniques such as encrypted code sections, in-stack encrypted strings, and return address manipulation. It also performs direct syscalls to bypass Windows NT APIs and evade detection by security tools. Furthermore, SquidLoader checks for the presence of debuggers and specific files, altering its behavior or terminating if such conditions are met.

The advanced evasion and strategies of SquidLoader represent a significant threat, capable of avoiding both static and dynamic analysis. The observed campaigns have predominantly targeted Chinese-speaking victims, but the techniques used by this threat actor could be adopted by others to target a broader range of organizations. Continuous monitoring and analysis are essential to protect against this evolving threat, and organizations should remain vigilant and adopt robust cybersecurity measures to mitigate potential risks.

THREAT PROFILE:

Tactic Technique Id Technique
Reconnaissance T1589 Gather Victim Identity Information
 Initial Access T1566 Phishing
Defense Evasion T1036 Masquerading
T1127 Trusted Developer Utilities Proxy Execution
T1140 Deobfuscate/Decode Files or Information
T1480 Execution Guardrails
 T1622 Debugger Evasion
Command and Control T1573 Encrypted Channel

REFERENCES:

The following reports contain further technical details:

https://cybersecurity.att.com/blogs/labs-research/highly-evasive-squidloader-targets-chinese-organizations

[/emaillocker]
crossmenu