Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
MalwareLatrodectus | Latrodectus can resolve Windows APIs dynamically by hash. |
| T1027.009 Embedded Payloads |
GroupTA577 | TA577 has used LNK files to execute embedded DLLs. |
| T1027.013 Encrypted/Encoded File |
MalwareLatrodectus | Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings. |
| T1041 Exfiltration Over C2 Channel |
MalwareLatrodectus | Latrodectus can exfiltrate encrypted system information to the C2 server. |
| T1053.005 Scheduled Task |
MalwareLatrodectus | Latrodectus can create scheduled tasks for persistence. |
| T1057 Process Discovery |
MalwareLatrodectus | Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1059.003 Windows Command Shell |
GroupTA577 | TA577 has used BAT files in malware execution chains. |
| T1059.007 JavaScript |
GroupTA577 | TA577 has used JavaScript to execute additional malicious payloads. |
| T1059.007 JavaScript |
GroupTA578 | TA578 has used JavaScript files in malware execution chains. |
| T1071.001 Web Protocols |
MalwareLatrodectus | Latrodectus can send registration information to C2 via HTTP `POST`. |
| T1082 System Information Discovery |
MalwareLatrodectus | Latrodectus can gather operating system information. |
| T1083 File and Directory Discovery |
MalwareLatrodectus | Latrodectus can collect desktop filenames. |
| T1104 Multi-Stage Channels |
MalwareLatrodectus | Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareLatrodectus | Latrodectus can download and execute PEs, DLLs, and shellcode from C2. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1132.001 Standard Encoding |
MalwareLatrodectus | Latrodectus has Base64-encoded the message body of a HTTP request sent to C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLatrodectus | Latrodectus has the ability to deobfuscate encrypted strings. |
| T1204.001 Malicious Link |
MalwareLatrodectus | Latrodectus has been executed through malicious links distributed in email campaigns. |
| T1204.001 Malicious Link |
GroupTA578 | TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads. |
| T1204.001 Malicious Link |
GroupTA577 | TA577 has lured users into executing malicious JavaScript files by sending malicious links via email. |
| T1218.007 Msiexec |
MalwareLatrodectus | Latrodectus has called `msiexec` to install remotely-hosted MSI files. |
| T1497.001 System Checks |
MalwareLatrodectus | Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLatrodectus | Latrodectus can set an AutoRun key to establish persistence. |
| T1566.002 Spearphishing Link |
MalwareLatrodectus | Latrodectus has been distributed to victims through emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupTA577 | TA577 has sent emails containing links to malicious JavaScript files. |
| T1573.001 Symmetric Cryptography |
MalwareLatrodectus | Latrodectus can send RC4 encrypted data over C2 channels. |
| T1583.006 Web Services |
GroupTA578 | TA578 has used Google Firebase to host malicious scripts. |
| T1586.002 Email Accounts |
GroupTA577 | TA577 has sent thread hijacked messages from compromised emails. |
| T1594 Search Victim-Owned Websites |
GroupTA578 | TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs. |
| T1622 Debugger Evasion |
MalwareLatrodectus | Latrodectus has the ability to check for the presence of debuggers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.