Malware & Threats

Highly Evasive SquidLoader Malware Targets China

A threat actor targeting Chinese-speaking victims has been using the SquidLoader malware loader in recent attacks.

A threat actor targeting Chinese-speaking victims has been using the SquidLoader malware loader in recent attacks.

A recently discovered malware loader dubbed SquidLoader is linked to an unknown threat actor that has been targeting Chinese-speaking victims for two years, LevelBlue Labs (formerly AT&T Alien Labs) reports.

SquidLoader was first observed at the end of April, but LevelBlue Labs believes that it had been active for at least a month before. The threat actor using it, however, has been focusing on entities in China for much longer.

The recently observed attacks start with phishing emails delivering malware loaders masquerading as documents intended for Chinese organizations. When executed, the loaders fetched and executed shellcode payloads in the loader process’ memory.

“Due to all the decoy and evasion techniques observed in this loader, and the absence of previous similar samples, LevelBlue Labs has named this malware ‘SquidLoader’,” LevelBlue explains.

Identified SquidLoader samples had been signed with a legitimate, albeit expired, certificate and would connect to command-and-control (C&C) servers that use a self-signed certificate.

Upon execution, the malware loader first duplicates itself to a predefined location using an innocuous name, likely as a decoy technique. In fact, the malware uses various other decoys, as well as multiple evasion techniques to ensure it can remain under the radar.

Advertisement. Scroll to continue reading.

Some of the observed techniques include pointless or obscure instructions, encrypted code sections, in-stack encrypted strings, jumps to the middle of instructions, return address obfuscation, Control Flow Graph (CFG) obfuscation, debugger detection, and direct syscalls.

During its investigation, LevelBlue Labs observed the malware loader delivering a single payload, namely a Cobalt Strike beacon featuring a configuration previously observed in multiple campaigns targeting Chinese-speaking users.

The observed tools, techniques, and procedures (TTPs) align with those of an advanced persistent threat (APT) actor, but LevelBlue Labs says it does not have enough data to classify this threat actor as an APT.

“Given the success SquidLoader has shown in evading detection, it is likely that threat actors targeting demographics beyond China will start to mimic the techniques used by the threat actor responsible for SquidLoader, helping them to to elude detection and analysis on their unique malware samples,” LevelBlue Labs says.

Related: Chinese Hackers Leveraged Legacy F5 BIG-IP Appliance for Persistence

Related: Multiple Chinese APTs Targeted Southeast Asian Government for Two Years

Related: Long-Standing Chinese Cybercrime Campaign Spoofs Over 400 Brands

Related Content

Malware & Threats

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Malware & Threats

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Artificial Intelligence

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.

Artificial Intelligence

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.

Malware & Threats

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version