Malware.View on attack.mitre.org
Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Latrodectus can collect data from a compromised host using a stealer module. |
| T1016 System Network Configuration Discovery |
Latrodectus can discover the IP and MAC address of a targeted host. |
| T1021.005 VNC |
Latrodectus has routed C2 traffic using Keyhole VNC. |
| T1027.001 Binary Padding |
Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file. |
| T1027.002 Software Packing |
The Latrodectus payload has been packed for obfuscation. |
| T1027.007 Dynamic API Resolution |
Latrodectus can resolve Windows APIs dynamically by hash. |
| T1027.013 Encrypted/Encoded File |
Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings. |
| T1033 System Owner/User Discovery |
Latrodectus can discover the username of an infected host. |
| T1036.005 Match Legitimate Resource Name or Location |
Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS. |
| T1041 Exfiltration Over C2 Channel |
Latrodectus can exfiltrate encrypted system information to the C2 server. |
| T1047 Windows Management Instrumentation |
Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files. |
| T1053.005 Scheduled Task |
Latrodectus can create scheduled tasks for persistence. |
| T1057 Process Discovery |
Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1059.003 Windows Command Shell |
The Latrodectus command handler can use `cmdexe` to run multiple discovery commands. |
| T1059.007 JavaScript |
Latrodectus has used JavaScript files as part its infection chain during malicious spam |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.