Malicious Latrodectus Downloader Picks Up Where QBot Left Off
ID: 3f7d969a-bf4e-5975-8179-cacb96d153e0
STIX ID: report--3f7d969a-bf4e-5975-8179-cacb96d153e0
Feed Name: Dark Reading
Date Published: 2024-04-04
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
The report describes Latrodectus, a newly identified downloader observed since late 2023 and increasingly used in phishing email campaigns by initial access brokers (notably TA577 and TA578). Latrodectus implements sandbox-evasion checks, has seen rising activity in Feb–Mar 2024, and is likely filling the operational gap left by the QBot takedown, prompting recommendations for enhanced phishing awareness and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
