logo

Following the spiders: Investigating Latrodectus malware

ID: 9acb2227-5e64-5284-a479-1f1ecd0e13b7

STIX ID: report--9acb2227-5e64-5284-a479-1f1ecd0e13b7

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2025-05-23

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Expel describes the Latrodectus malware loader leveraging the ClickFix social-engineering trick to have users execute obfuscated PowerShell that installs an MSI which sideloads a malicious DLL; the chain results in in-memory execution and deployment of RATs/infostealers and ransomware. The report breaks down the PowerShell payload, explains the infection and sideloading mechanics, offers mitigations (disable Windows Run/GPO or hotkey), and provides observed IOCs including file hashes, domains, IPs, and abused code-signing certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.