Latrodectus Loader
ID: 45041cf1-ad12-55ea-a2ea-7428150785af
STIX ID: report--45041cf1-ad12-55ea-a2ea-7428150785af
Feed Name: Pulsedive Blog
This report analyzes Latrodectus, a recently observed Windows loader used by multiple threat actors (notably TA577 and TA578) to deliver secondary payloads such as IcedID and Lumma Stealer via email-based infection chains (malicious JS, MSI via WebDAV, ISO/LNK). It details C2 behavior (RC4+Base64 POSTs, reusable key), command handlers, runtime API resolving, anti-analysis checks, a large set of network IoCs, MITRE ATT&CK mappings, and detection recommendations including Suricata rules and host-based monitoring guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
