logo

New Latrodectus malware attacks use Microsoft, Cloudflare themes

ID: 785df819-4de5-5da6-b25f-bc42080166b6

STIX ID: report--785df819-4de5-5da6-b25f-bc42080166b6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-30

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Latrodectus (aka Unidentified 111 / IceNova) is being distributed via reply-chain phishing that uses PDF attachments and fake Cloudflare captchas to trick users into downloading an obfuscated JavaScript which fetches an MSI; the MSI installs a DLL in %AppData% that is launched via rundll32 and functions as a downloader/backdoor. Researchers link the campaign to IcedID developers and have observed it dropping Lumma and Danabot, presenting a significant risk of credential theft and subsequent malware escalation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.