LATRODECTUS Malware Loader: Threat Poised to Replace ICEDID
ID: 30c4b302-e3e0-58d4-a542-7cb57820d180
STIX ID: report--30c4b302-e3e0-58d4-a542-7cb57820d180
Feed Name: securityonline.info
Elastic Security Labs reports on LATRODECTUS, a lightweight malware loader observed since March 2024 in email campaigns targeting financial institutions and individuals. The loader is delivered via oversized JavaScript invoking msiexec to install remote MSI files over WEBDAV, employs string obfuscation, runtime API resolution via the PEB and CRC32, and multiple anti-analysis checks (debugger, process counts, WOW64, MAC validation). It persists via scheduled tasks created through COM, self-deletes to hinder response, communicates with C2 using base64 and RC4 with a hardcoded password, and contains command handlers for enumeration, process discovery, file listing, payload download/execution and executing ICEDID components, indicating a developmental link to ICEDID.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
