Following the spiders: Investigating Latrodectus malware
ID: 9acb2227-5e64-5284-a479-1f1ecd0e13b7
STIX ID: report--9acb2227-5e64-5284-a479-1f1ecd0e13b7
Feed Name: Expel Blog
Expel describes the Latrodectus malware loader leveraging the ClickFix social-engineering trick to have users execute obfuscated PowerShell that installs an MSI which sideloads a malicious DLL; the chain results in in-memory execution and deployment of RATs/infostealers and ransomware. The report breaks down the PowerShell payload, explains the infection and sideloading mechanics, offers mitigations (disable Windows Run/GPO or hotkey), and provides observed IOCs including file hashes, domains, IPs, and abused code-signing certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
