logo

Latrodectus Malware Masquerades as AhnLab Security Software to Infect Victims

ID: 5b75e81b-13a2-5fd3-b83a-55c34524ad33

STIX ID: report--5b75e81b-13a2-5fd3-b83a-55c34524ad33

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report analyzes the Latrodectus downloader (MeDExt.dll), detailing its malicious behavior (COM-based scheduled task persistence), C2 communications, and infrastructure discovered via TLS certificate pivoting; it lists multiple associated domains, IPs, and file hashes and highlights the risk of the downloader deploying additional payloads (notably Brute Ratel C4).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.