Malicious users have once again turned to an older trick known as Squiblydoo to spread Qbot and Lokibot, via a Microsoft Office using regsvr32.exe.

See also: LokiBot: CISA warns of increase in malware activity
A report from the threat research team of security analytics platform Uptycsshows that the use of regsvr32.exe has increased over the past two months, via various document formats but mainly Excel files.
The sudden focus on this particular command line utility is explained by the fact that it allows malicious users to bypass the application block list, which could stop the infection chain.
Telemetry data collected from Uptyck customers shows that December 2021 recorded the most incidents of Windows tool abuse, but the high rates continued into 2022.
regsvr32 is a Windows command-line utility used to register and unregister OLE (DLLs and ActiveX controls) in the registry.
See also: Qbot malware takes only 30 minutes to steal information
Threat actors abuse the utility not to make registry modifications, but to load COM scriptlets from a remote source using DLL (scrobj.dll).

To this end, they use regsvr32 to register OCX files, which are special-purpose software modules that can call ready-made components such as DLL files.
This technique is called “Squiblydoo” and has been used in malware drop operations since 2017. In the current campaign, hackers are using Excel, Word, RTF, and complex document files with malicious macros that launch the regsvr32 process.
These documents are typically distributed through phishing, although they can also be delivered through “blind” SEO poisoning attacks.
The above method provides good evasion for the malware payload because regsvr32 is a Windows tool used for multiple routine functions.
See also: QBot malware: Microsoft analyzes the building blocks of attacks
Therefore, security solutions are less likely to detect the threat and intervene to end the infection chain.
Also, using remote COM scriptlets allows attackers to load malware without files. Since these payloads are executed from within the document, their chances of detection are lower.
