logo

LATRODECTUS Malware Loader: Threat Poised to Replace ICEDID

ID: 30c4b302-e3e0-58d4-a542-7cb57820d180

STIX ID: report--30c4b302-e3e0-58d4-a542-7cb57820d180

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2024-05-20

Date Updated: 2026-04-22

Author: do son

...
...

Elastic Security Labs reports on LATRODECTUS, a lightweight malware loader observed since March 2024 in email campaigns targeting financial institutions and individuals. The loader is delivered via oversized JavaScript invoking msiexec to install remote MSI files over WEBDAV, employs string obfuscation, runtime API resolution via the PEB and CRC32, and multiple anti-analysis checks (debugger, process counts, WOW64, MAC validation). It persists via scheduled tasks created through COM, self-deletes to hinder response, communicates with C2 using base64 and RC4 with a hardcoded password, and contains command handlers for enumeration, process discovery, file listing, payload download/execution and executing ICEDID components, indicating a developmental link to ICEDID.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.