Cybersecurity researchers have discovered Evasive SquidLoader, a new loader malware that evades detection and spreads through phishing campaigns targeting Chinese organizations .

AT&T LevelBlue Labs detected the malware in late April 2024 and reported that it incorporates features designed to hinder both static and dynamic analysis, making detection difficult.
Read more: Void Arachne: Uses Deepfake and AI to spread malicious VPNs
The attacks begin with phishing that include attachments disguised as Microsoft Word. In reality, they are binary files that pave the way for the malware to execute, which then downloads second-stage payloads from a remote server, such as Cobalt Strike.
“These loaders have sophisticated evasion and deception mechanisms that help them remain undetected and make analysis difficult,” said security researcher Fernando Dominguez. “The shellcode is also loaded in the same process, thus avoiding writing the payload to disk and reducing the risk of detection.”
Some of the evasion techniques used by SquidLoader include encrypted code fragments, redundant and unused code, Control Flow Graph (CFG) obfuscation, debug tracing, and executing direct system calls instead of Windows NT API calls
The malware loader has become popular for threat actors looking to deliver and launch additional payloads to compromised hosts, while bypassing antivirus defenses and other security measures. Last year, Aon Stroz Friedberg detailed a loader, known as Taurus Loader, that has been used to distribute the Taurus information stealer as well as AgentVX, a trojan with capabilities to execute more malware and set up persistence through changes to the Windows and data collection.
See related: New malware targets exposed Docker APIs for cryptocurrency mining
The development continues as a new, in-depth analysis of the malware loader and backdoor known as PikaBot indicates that the software has been actively developed by its developers since its appearance in February 2023.
“The malware uses advanced anti-analysis techniques to evade detection and make analysis difficult, including system checks, indirect system calls, encryption , and dynamic API analysis,” Sekoia said. “Recent updates to the malware have further enhanced its capabilities, making it even more difficult to detect and counter.”
Meanwhile, findings from BitSight reveal that infrastructure associated with the Latrodectus loader malware was taken offline following the law enforcement operation dubbed Operation Endgame. During this operation, more than 100 botnet servers were taken down, including those associated with IcedID, SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot.

Read more: Markopolo scam targets crypto users
The cybersecurity firm said it identified nearly 5,000 different victims across 10 separate campaigns. The majority of victims were found in the US, UK, Netherlands, Poland, France, Czech Republic, Japan, Australia, Germany and Canada.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
