Squid Werewolf

2025-03-12 • Bi ZoneSquid Werewolf cyber spies masquerade as recruite…

Squid Werewolf is a cyber-espionage cluster identified by BI.ZONE, which in December 2024 uncovered a phishing campaign impersonating an industrial organization's HR representative to lure targets with fake job offers, and attributed the activity to a cluster tracked elsewhere as APT37, Ricochet Chollima, ScarCruft, and Reaper Group. The campaign delivered a password-protected archive containing a malicious shortcut file disguised as a PDF job offer; opening it ran a command that decoded an embedded payload, copied a legitimate system utility into a startup folder to gain persistence, and side-loaded a custom, obfuscated loader through a code-injection technique. The loader checks internet connectivity and its own runtime duration to evade sandbox analysis, disables startup-folder autorun notifications, and either loads a locally cached, encrypted payload or fetches and decrypts one from its command-and-control server for execution in memory. BI.ZONE noted this activity closely resembles a previously reported cluster that used a similarly structured loader to deliver a remote access trojan.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster