Recommended Free Tools
SquidLoader is a malware loader first reported by LevelBlue Labs in campaigns observed in late April 2024, including activity targeting Chinese-speaking victims. A separate Trellix report in July 2025 described a SquidLoader sample used against Hong Kong financial-sector employees and noted samples suggesting activity in Singapore and Australia. The reports document phishing lures, anti-analysis techniques, and delivery of Cobalt Strike Beacon, but they do not establish a confirmed operator or state sponsor.
What SquidLoader is—and what the name does not establish
LevelBlue Labs researcher Fernando Dominguez named SquidLoader in a report published June 19, 2024. The team said it first observed the loader in campaigns in late April 2024 and predicted it had been active for at least a month before discovery. The name identifies the malware described by researchers; it is not a name known to have been chosen by its operator.
A loader is malware that helps bring another payload onto a system or run it. In the samples discussed by LevelBlue and Trellix, that later payload was a Cobalt Strike Beacon. Cobalt Strike is a legitimate security testing framework whose Beacon component can also be used by attackers for command-and-control activity. Its presence alone does not identify who operated a particular campaign.
How the 2024 and 2025 reports differ
The two reports should be read as separate observations, not as proof of one unchanged campaign or a single infection chain. Details such as lure format, checks, and command-and-control infrastructure are specific to the analyzed samples.
#1 Best Overall
| Reporting | Targeting and delivery described | Sample behavior and payload | What the report supports |
|---|---|---|---|
| LevelBlue Labs, June 19, 2024 | Campaigns first observed in late April 2024, mainly targeting Chinese-speaking victims. Executable attachments used Word-document icons and filenames referring to Chinese companies or institutions. | In the analyzed sample, the loader downloaded shellcode from a /flag.jpg URI over HTTPS; the shellcode ran in the loader process. The observed second-stage payload was a modified Cobalt Strike sample. |
Evidence of China-focused targeting and the behaviors of the analyzed 2024 sample. It does not show that every named organization was compromised. |
| Trellix, July 15, 2025 | A wave aimed at employees of Hong Kong financial services institutions used a Mandarin-language spear-phishing email and a password-protected RAR archive presented as an invoice, containing a disguised PE executable. Trellix also described samples suggesting regional variation involving Singapore and Australia. | The analyzed sample performed multiple environmental and anti-analysis checks, sent host information to a command-and-control server, and downloaded and executed a Cobalt Strike Beacon. The loader and Beacon stages contacted different C2 infrastructure. | Evidence about the 2025 Hong Kong-focused reporting and related samples; it does not prove that the victim set or delivery chain was identical to the 2024 activity. |
How the reported samples reached victims
LevelBlue’s 2024 observations
LevelBlue saw executables that appeared to be phishing attachments. They carried Word-document icons despite being executable binaries, and their descriptive filenames referred to entities including China Mobile Group Shaanxi Co Ltd, Jiaqi Intelligent Technology, and the Yellow River Conservancy Technical Institute. One filename translated as “Huawei industrial-grade router related product introduction and excellent customer cases.” These lure details show how the files were presented; they do not demonstrate that the referenced organizations were breached or involved.
LevelBlue also noted that a Cobalt Strike Beacon configuration had appeared in sporadic campaigns over the preceding two years. That observation does not mean every such campaign used SquidLoader or that all the activity shared an operator.
Trellix’s 2025 sample
Trellix described a Mandarin-language spear-phishing message to Hong Kong financial-sector employees. The message led recipients to a password-protected RAR archive framed as an invoice; the archive contained a PE executable disguised as a document. The report’s evidence concerns this sample and campaign context, not a universal SquidLoader delivery method.
How the analyzed malware behaved
LevelBlue’s 2024 sample: shellcode and decoys
In LevelBlue’s analyzed sample, SquidLoader made an HTTPS GET request to a /flag.jpg URI to download shellcode. The shellcode was encrypted with a five-byte XOR key. After accounting for little-endian storage, the reported key was DE FF CC 8F 9A. It ran in the loader’s process, which LevelBlue said likely avoided writing the payload to disk. The resulting second-stage payload was a modified Cobalt Strike sample hardened against static analysis.
LevelBlue described other decoy features: descriptive filenames, Word-like icons, an expired certificate on most samples it observed, and code or metadata referencing legitimate software such as WeChat and mingw-gcc. The report said some apparent software code was not reached because execution transferred to the payload earlier. In the sample it analyzed, the loader copied itself to C:BakFilesinstall.exe and restarted from there. LevelBlue said the loader did not implement persistence itself; the delivered Cobalt Strike payload could establish persistence on demand by creating services or modifying registry keys.
Trellix’s 2025 sample: environmental checks and reporting
Trellix documented a more extensive anti-analysis sequence in its sample. It unpacked internal code, resolved Windows APIs dynamically, checked usernames and running process names associated with analysis tools, and performed debugger and sandbox checks. It also used thread and delay behavior. After its checks, it displayed a Mandarin message saying the file was corrupted and could not be opened.
The sample sent host information to a command-and-control server, including the IP address, username, computer name, Windows version, process and thread IDs, filename, and privilege status. It then downloaded and executed a Cobalt Strike Beacon. Trellix reported separate C2 infrastructure for the loader and Beacon stages. These behaviors describe the sample Trellix analyzed, not a complete specification for all SquidLoader activity.
What is known about attribution—and what is not
LevelBlue explicitly cautioned against treating the available evidence as a confirmed APT attribution. Dominguez wrote: “Analysis in this report may not include enough data to classify this threat actor as an APT, however, the TTPs observed from this threat actor resemble those of an APT.” Resemblance to techniques associated with advanced persistent threats does not establish APT status, identify a group, or prove national affiliation or state sponsorship.
Best Value
The reporting supports technical observations and geographic targeting claims: LevelBlue’s 2024 China-focused account, and Trellix’s 2025 Hong Kong financial-sector report plus samples suggesting Singapore and Australia. It does not establish that all these observations came from one campaign or the same victim population.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Using indicators and findings defensively
Indicators of compromise (IOCs) such as file hashes, IP addresses, domains, and C2 paths can help investigate specific samples, but they are time-sensitive and should not be treated as a complete or permanent blocklist. LevelBlue’s public IOC landing page reiterates the discovery timeframe but makes the IOC report available through a download flow; the full indicator set is not exposed on that page. Trellix publishes indicators associated with the samples it analyzed.
For defenders, the reports make several practical controls relevant without demonstrating that any particular security product detects or blocks SquidLoader:
- Use mail controls and user reporting processes that make suspicious attachments and password-protected archives easier to inspect and escalate.
- Monitor endpoint behavior for unexpected executable launches, suspicious process or thread activity, and unusual outbound connections, including staged payload downloads.
- When investigating an alert, preserve the original message and attachment, record the sample hash and observed network indicators, and compare them with current threat intelligence rather than relying on an old indicator list alone.
- Assess persistence and follow-on activity separately. In LevelBlue’s sample the loader itself did not establish persistence, while its delivered payload could do so.
Trellix described its sample’s VirusTotal detection as “near-zero” at the time of its analysis, but did not provide a count or rate. That is a time-bound observation about that sample, not a general detection percentage or evidence that a given antivirus or endpoint product will miss the malware.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

