Squid Werewolf
2025-03-12 • Bi Zone • Squid Werewolf cyber spies masquerade as recruite…
Squid Werewolf is a cyber-espionage cluster identified by BI.ZONE, which in December 2024 uncovered a phishing campaign impersonating an industrial organization's HR representative to lure targets with fake job offers, and attributed the activity to a cluster tracked elsewhere as APT37, Ricochet Chollima, ScarCruft, and Reaper Group. The campaign delivered a password-protected archive containing a malicious shortcut file disguised as a PDF job offer; opening it ran a command that decoded an embedded payload, copied a legitimate system utility into a startup folder to gain persistence, and side-loaded a custom, obfuscated loader through a code-injection technique. The loader checks internet connectivity and its own runtime duration to evade sandbox analysis, disables startup-folder autorun notifications, and either loads a locally cached, encrypted payload or fetches and decrypts one from its command-and-control server for execution in memory. BI.ZONE noted this activity closely resembles a previously reported cluster that used a similarly structured loader to deliver a remote access trojan.
-
26
Related Actors
-
284
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Squid Werewolf reports only