ATT&CKReferencesLatrodectus APR 2024

Latrodectus APR 2024

Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

Open the source

Techniques1

Groups2

Software1

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1027.007
Dynamic API Resolution
MalwareLatrodectus

Latrodectus can resolve Windows APIs dynamically by hash.

T1027.009
Embedded Payloads
GroupTA577

TA577 has used LNK files to execute embedded DLLs.

T1027.013
Encrypted/Encoded File
MalwareLatrodectus

Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings.

T1041
Exfiltration Over C2 Channel
MalwareLatrodectus

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1053.005
Scheduled Task
MalwareLatrodectus

Latrodectus can create scheduled tasks for persistence.

T1057
Process Discovery
MalwareLatrodectus

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1059.003
Windows Command Shell
GroupTA577

TA577 has used BAT files in malware execution chains.

T1059.007
JavaScript
GroupTA577

TA577 has used JavaScript to execute additional malicious payloads.

T1059.007
JavaScript
GroupTA578

TA578 has used JavaScript files in malware execution chains.

T1071.001
Web Protocols
MalwareLatrodectus

Latrodectus can send registration information to C2 via HTTP `POST`.

T1082
System Information Discovery
MalwareLatrodectus

Latrodectus can gather operating system information.

T1083
File and Directory Discovery
MalwareLatrodectus

Latrodectus can collect desktop filenames.

T1104
Multi-Stage Channels
MalwareLatrodectus

Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure.

T1105
Ingress Tool Transfer
MalwareLatrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1132.001
Standard Encoding
MalwareLatrodectus

Latrodectus has Base64-encoded the message body of a HTTP request sent to C2.

T1140
Deobfuscate/Decode Files or Information
MalwareLatrodectus

Latrodectus has the ability to deobfuscate encrypted strings.

T1204.001
Malicious Link
MalwareLatrodectus

Latrodectus has been executed through malicious links distributed in email campaigns.

T1204.001
Malicious Link
GroupTA578

TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads.

T1204.001
Malicious Link
GroupTA577

TA577 has lured users into executing malicious JavaScript files by sending malicious links via email.

T1218.007
Msiexec
MalwareLatrodectus

Latrodectus has called `msiexec` to install remotely-hosted MSI files.

T1497.001
System Checks
MalwareLatrodectus

Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address.

T1547.001
Registry Run Keys / Startup Folder
MalwareLatrodectus

Latrodectus can set an AutoRun key to establish persistence.

T1566.002
Spearphishing Link
MalwareLatrodectus

Latrodectus has been distributed to victims through emails containing malicious links.

T1566.002
Spearphishing Link
GroupTA577

TA577 has sent emails containing links to malicious JavaScript files.

T1573.001
Symmetric Cryptography
MalwareLatrodectus

Latrodectus can send RC4 encrypted data over C2 channels.

T1583.006
Web Services
GroupTA578

TA578 has used Google Firebase to host malicious scripts.

T1586.002
Email Accounts
GroupTA577

TA577 has sent thread hijacked messages from compromised emails.

T1594
Search Victim-Owned Websites
GroupTA578

TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs.

T1622
Debugger Evasion
MalwareLatrodectus

Latrodectus has the ability to check for the presence of debuggers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.