ATT&CKSoftwareLatrodectus

Latrodectus

S1160

Malware.View on attack.mitre.org

About this malware

Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.

Techniques used43

Procedure examples43

TechniqueProcedure example
T1005
Data from Local System

Latrodectus can collect data from a compromised host using a stealer module.

T1016
System Network Configuration Discovery

Latrodectus can discover the IP and MAC address of a targeted host.

T1021.005
VNC

Latrodectus has routed C2 traffic using Keyhole VNC.

T1027.001
Binary Padding

Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file.

T1027.002
Software Packing

The Latrodectus payload has been packed for obfuscation.

T1027.007
Dynamic API Resolution

Latrodectus can resolve Windows APIs dynamically by hash.

T1027.013
Encrypted/Encoded File

Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings.

T1033
System Owner/User Discovery

Latrodectus can discover the username of an infected host.

T1036.005
Match Legitimate Resource Name or Location

Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS.

T1041
Exfiltration Over C2 Channel

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1047
Windows Management Instrumentation

Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files.

T1053.005
Scheduled Task

Latrodectus can create scheduled tasks for persistence.

T1057
Process Discovery

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1059.003
Windows Command Shell

The Latrodectus command handler can use `cmdexe` to run multiple discovery commands.

T1059.007
JavaScript

Latrodectus has used JavaScript files as part its infection chain during malicious spam
email campaigns.

View all 43 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. Bitsight Latrodectus June 2024 Open source
    Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.
  2. Bleeping Computer Latrodectus April 2024 Open source
    Abrams, L. (2024, April 30). New Latrodectus malware attacks use Microsoft, Cloudflare themes. Retrieved September 13, 2024.
  3. Latrodectus APR 2024 Open source
    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.