ATT&CKReferencesElastic Latrodectus May 2024

Elastic Latrodectus May 2024

Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLatrodectus

Latrodectus can discover the IP and MAC address of a targeted host.

T1027.001
Binary Padding
MalwareLatrodectus

Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file.

T1027.002
Software Packing
MalwareLatrodectus

The Latrodectus payload has been packed for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareLatrodectus

Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings.

T1033
System Owner/User Discovery
MalwareLatrodectus

Latrodectus can discover the username of an infected host.

T1036.005
Match Legitimate Resource Name or Location
MalwareLatrodectus

Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS.

T1047
Windows Management Instrumentation
MalwareLatrodectus

Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files.

T1053.005
Scheduled Task
MalwareLatrodectus

Latrodectus can create scheduled tasks for persistence.

T1057
Process Discovery
MalwareLatrodectus

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1059.003
Windows Command Shell
MalwareLatrodectus

The Latrodectus command handler can use `cmdexe` to run multiple discovery commands.

T1059.007
JavaScript
MalwareLatrodectus

Latrodectus has used JavaScript files as part its infection chain during malicious spam
email campaigns.

T1069.002
Domain Groups
MalwareLatrodectus

Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`.

T1070.004
File Deletion
MalwareLatrodectus

Latrodectus has the ability to delete itself.

T1071.001
Web Protocols
MalwareLatrodectus

Latrodectus can send registration information to C2 via HTTP `POST`.

T1082
System Information Discovery
MalwareLatrodectus

Latrodectus can gather operating system information.

T1083
File and Directory Discovery
MalwareLatrodectus

Latrodectus can collect desktop filenames.

T1087.002
Domain Account
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts.

T1105
Ingress Tool Transfer
MalwareLatrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.

T1106
Native API
MalwareLatrodectus

Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`.

T1132.001
Standard Encoding
MalwareLatrodectus

Latrodectus has Base64-encoded the message body of a HTTP request sent to C2.

T1135
Network Share Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareLatrodectus

Latrodectus has the ability to deobfuscate encrypted strings.

T1218.011
Rundll32
MalwareLatrodectus

Latrodectus can use rundll32.exe to execute downloaded DLLs.

T1482
Domain Trust Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts.

T1497.001
System Checks
MalwareLatrodectus

Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address.

T1518.001
Security Software Discovery
MalwareLatrodectus

Latrodectus has the ability to identify installed antivirus products.

T1529
System Shutdown/Reboot
MalwareLatrodectus

Latrodectus has the ability to restart compromised hosts.

T1559.001
Component Object Model
MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

T1564.004
NTFS File Attributes
MalwareLatrodectus

Latrodectus can delete itself while its process is still running through the use of an alternate data stream.

T1573.001
Symmetric Cryptography
MalwareLatrodectus

Latrodectus can send RC4 encrypted data over C2 channels.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.