Latrodectus Malware Masquerades as AhnLab Security Software to Infect Victims
ID: 5b75e81b-13a2-5fd3-b83a-55c34524ad33
STIX ID: report--5b75e81b-13a2-5fd3-b83a-55c34524ad33
Feed Name: Hunt.io Blog
Threat Score
This report analyzes the Latrodectus downloader (MeDExt.dll), detailing its malicious behavior (COM-based scheduled task persistence), C2 communications, and infrastructure discovered via TLS certificate pivoting; it lists multiple associated domains, IPs, and file hashes and highlights the risk of the downloader deploying additional payloads (notably Brute Ratel C4).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
